Skip to main content

Year archive

CVEs published in 2012

Archive summary

5,288 CVEs published in 2012 — 950 Critical, 794 High, 3,036 Medium, 506 Low, 2 Unrated.

CVE-2012-1034

Published Feb 8, 2012

Multiple cross-site scripting (XSS) vulnerabilities in the admin interface in EPiServer CMS through 6R2 allow remote attackers to inject arbitrary web script or HTML via unspecifi…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1031

Published Feb 8, 2012

Unspecified vulnerability in EPiServer CMS 5 and 6 through 6R2, in certain configurations using Forms Authentication, allows remote authenticated users to obtain WebAdmins access…

CVSS 6.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1008

Published Feb 8, 2012

OfficeSIP Server 3.1 allows remote attackers to cause a denial of service (daemon crash) via a crafted To header in a SIP INVITE message.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1004

Published Feb 8, 2012

Multiple cross-site scripting (XSS) vulnerabilities in UI/Register.pm in Foswiki before 1.1.5 allow remote authenticated users with CHANGE privileges to inject arbitrary web scrip…

CVSS 2.1 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-1002

Published Feb 8, 2012

SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid parameter.

CVSS 10.0 · Critical
Vendor/product tagsBeta · best-effort

CVE-2012-1029

Published Feb 8, 2012

SQL injection vulnerability in mobile/search/index.php in Tube Ace (Adult PHP Tube Script) 1.6 allows remote attackers to execute arbitrary SQL commands via the q parameter. NOTE…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1028

Published Feb 8, 2012

Cross-site scripting (XSS) vulnerability in bin/index.php in SimpleGroupware 0.742 and other versions before 0.743 allows remote attackers to inject arbitrary web script or HTML v…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1027

Published Feb 8, 2012

Cross-site scripting (XSS) vulnerability in account-closed.tcl in ]project-open[ (aka ]po[) 3.4.x, 3.5.0.1-2, and possibly other versions allows remote attackers to inject arbitra…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1026

Published Feb 8, 2012

Multiple SQL injection vulnerabilities in login2.php in XRay CMS 1.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) username or (2) password parameters.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1025

Published Feb 8, 2012

Absolute path traversal vulnerability in file in Enigma2 Webinterface 1.6.0 through 1.6.8, 1.6rc3, and 1.7.0 allows remote attackers to read arbitrary files via a full pathname in…

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1024

Published Feb 8, 2012

Directory traversal vulnerability in file in Enigma2 Webinterface 1.5rc1 and 1.5beta4 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVSS 5.0 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1023

Published Feb 8, 2012

Open redirect vulnerability in admin/index.php in 4images 1.7.10 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the red…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1022

Published Feb 8, 2012

SQL injection vulnerability in admin/categories.php in 4images 1.7.10 remote attackers to execute arbitrary SQL commands via the cat_parent_id parameter in an addcat action.

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2012-1021

Published Feb 8, 2012

Cross-site scripting (XSS) vulnerability in admin/categories.php in 4images 1.7.10 allows remote attackers to inject arbitrary web script or HTML via the cat_parent_id parameter i…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1020

Published Feb 8, 2012

Multiple cross-site scripting (XSS) vulnerabilities in login.php in NexorONE Online Banking allow remote attackers to inject arbitrary web script or HTML via the (1) visitor_langu…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1019

Published Feb 8, 2012

Multiple cross-site scripting (XSS) vulnerabilities in XWiki Enterprise 3.4 allow remote attackers to inject arbitrary web script or HTML via the (1) XWiki.XWikiComments_comment p…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-1017

Published Feb 8, 2012

Multiple SQL injection vulnerabilities in base_qry_main.php in Basic Analysis and Security Engine (BASE) 1.4.5 allow remote attackers to execute arbitrary SQL commands via the (1)…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5077

Published Feb 8, 2012

Unrestricted file upload vulnerability in attachement.php in HDWiki 5.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then ac…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2011-5076

Published Feb 8, 2012

SQL injection vulnerability in model/comment.class.php in HDWiki 5.0, 5.1, and possibly other versions allows remote attackers to execute arbitrary SQL commands via the PATH_INFO…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort
Showing 4,876-4,900 of 5,288 CVEsPage 196 of 212