CVE-2012-6047
Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that add a user to an arbitrary group via the users page...
Cross-site request forgery (CSRF) vulnerability in X7 Chat 2.0.5.1 and earlier allows remote attackers to hijack the authentication of administrators for requests that add a user to an arbitrary group via the users page...
Static code injection vulnerability in admin/banners.php in PHP Enter allows remote attackers to inject arbitrary PHP code into horad.php via the code parameter. Date published : 2012-11-26 http://www.securityfocus.com/bid/53426 http://packetstormsecurity.org/files/112536/PHP-Enter-Code-Injection.html
Cross-site scripting (XSS) vulnerability in gb/user/index.php in Ramui Forum, possibly 1.0 Beta, allows remote attackers to inject arbitrary web script or HTML via the query parameter. Date published : 2012-11-26 http://www.securityfocus.com/bid/53411 http://packetstormsecurity.org/files/112495/Ramui-Forum-Script-Cross-Site-Scripting.html
M-Player 0.4 allows remote attackers to cause a denial of service (crash) via a crafted MP3 file. Date published : 2012-11-26 http://www.securityfocus.com/bid/51318 http://www.exploit-db.com/exploits/18337
Cross-site scripting (XSS) vulnerability in downloads.php in PHP-Fusion 7.02.04 allows remote attackers to inject arbitrary web script or HTML via the cat_id parameter. Date published : 2012-11-26 http://www.securityfocus.com/bid/51365 http://packetstormsecurity.org/files/view/108542/phpfusion70204-xss.txt
GPSMapEdit 1.1.73.2 allows user-assisted remote attackers to cause a denial of service (crash) via a long string in a lst file. Date published : 2012-11-26 http://www.securityfocus.com/bid/51327 http://www.exploit-db.com/exploits/18339
Double free vulnerability in GreenBrowser before 6.0.1002, when the keyword search bar (F6) is activated, allows remote attackers to execute arbitrary code via a crafted iframe. Date published : 2012-11-26 http://www.securityfocus.com/bid/51393 http://archives.neohapsis.com/archives/bugtraq/2012-01/0079.html
Cross-site scripting (XSS) vulnerability in users.php in File King Advanced File Management 1.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter. Date published : 2012-11-26 http://www.securityfocus.com/bid/51339 http://packetstormsecurity.org/files/view/108466/afm134-xss.txt
SQL injection vulnerability in view_comments.php in YABSoft Advanced Image Hosting (AIH) Script, possibly 2.3, allows remote attackers to execute arbitrary SQL commands via the gal parameter. Date published : 2012-11-26 http://www.securityfocus.com/bid/51394 http://www.exploit-db.com/exploits/18352
admin/core/admin_func.php in razorCMS before 1.2.1 does not properly restrict access to certain administrator directories and files, which allows remote authenticated users to read, edit, rename, move, copy and delete files via the (1) dir...
The send_to_sourcefire function in manage_sql.c in OpenVAS Manager 3.x before 3.0.4 allows remote attackers to execute arbitrary commands via the (1) IP address or (2) port number field in an OMP request. Date published...
ar web content manager (AWCM) 2.2 does not restrict the number of comment records that can be submitted through HTTP requests, which allows remote attackers to cause a denial of service (disk consumption) via...
cookie_gen.php in ar web content manager (AWCM) 2.2 does not require authentication, which allows remote attackers to generate arbitrary cookies via the name parameter in conjunction with the content parameter. Date published : 2012-11-26...
tcsd in TrouSerS before 0.3.10 allows remote attackers to cause a denial of service (daemon crash) via a crafted type_offset value in a TCP packet to port 30003. Date published : 2012-11-26 http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=692649 http://sourceforge.net/tracker/index.php?func=detail&aid=3473554&group_id=126012&atid=704358