|
78542
|
Disclosed: 2012-01-24
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 4
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Opera Framed Content Handling Same Origin Policy Bypass XSS Weakness
|
|
78541
|
Disclosed: 2012-01-24
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 4
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | | |
|
Opera JavaScript Event HTML Element Referencing Local File Enumeration
|
|
78540
|
Disclosed: 2012-01-20
Description:
SAP NetWeaver contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'cc0Host', 'cc0Id', 'cc0Path', 'cc0Port', 'cc0Protocol', 'cc0ProxyHost', 'cc0ProxyPort', 'cc1Host', 'cc1Id', 'cc1Path', 'cc1Port', 'cc1Protocol', 'cc1ProxyHost' and 'cc1ProxyPort' parameters upon submission to the bcbadmSettings.jsp script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
Comments: 0, Blogs: 0, References: 7
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | - Coordinated Disclosure
- Vendor Verified
| |
|
SAP NetWeaver bcbadmSettings.jsp Multiple Parameter XSS
|
|
78539
|
Disclosed: 2012-01-20
Description:
SAP NetWeaver contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'ValueIndustry', 'ValueRegion' and 'ValueExtension' parameters upon submission to the system_context_settings.jsp script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
Comments: 0, Blogs: 0, References: 7
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | - Coordinated Disclosure
- Vendor Verified
| |
|
SAP NetWeaver system_context_settings.jsp Multiple Parameter XSS
|
|
78538
|
Disclosed: 2012-01-20
Description:
SAP NetWeaver contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate the 'TXVDestination' parameter upon submission to the TextContainerAdmin/administration_setup.jsp script. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
Comments: 0, Blogs: 0, References: 7
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | - Coordinated Disclosure
- Vendor Verified
| |
|
SAP NetWeaver TextContainerAdmin/administration_setup.jsp TXVDestination Parameter XSS
|
|
78537
|
Disclosed: 2011-10-19
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 7
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | - Coordinated Disclosure
- Vendor Verified
| |
|
SAP NetWeaver PFL_CHECK_OS_FILE_EXISTENCE Function Arbitrary File Enumeration
|
|
78536
|
Disclosed: 2012-01-20
Description:
Unknown / Incomplete
Comments: 0, Blogs: 0, References: 7
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | - Coordinated Disclosure
- Vendor Verified
| |
|
SAP NetWeaver Resource Access Control Handling Runtime Workbench Access Restriction Bypass
|
|
78535
|
Disclosed: 2012-01-24
Description:
(Description Provided by CVE) : ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.
Comments: 0, Blogs: 0, References: 4
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
- Local / Remote
- Context Dependent
| | | | | - Vendor Verified
- Coordinated Disclosure
| |
|
Ocean Data Systems Dream Report Write Access Violation File Handling Memory Corruption
|
|
78534
|
Disclosed: 2012-01-24
Description:
Ocean Data Systems Dream Report contains a flaw that allows a remote cross-site scripting (XSS) attack. This flaw exists because the application does not validate certain unspecified input before returning it to the user. This may allow a user to create a specially crafted URL that would execute arbitrary script code in a user's browser within the trust relationship between their browser and the server.
Comments: 0, Blogs: 0, References: 4
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | - Vendor Verified
- Coordinated Disclosure
| |
|
Ocean Data Systems Dream Report Unspecified XSS
|
|
78533
|
Disclosed: 2012-01-24
Description:
(Description Provided by CVE) : Symantec pcAnywhere 12.5.x through 12.5.3, and IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), uses world-writable permissions for product-installation files, which allows local users to gain privileges by modifying a file.
Comments: 0, Blogs: 0, References: 6
Vulnerability Classification
| Location | Attack Type | Impact | Solution | Exploit | Disclosure | OSVDB |
|---|
| | | | | - Vendor Verified
- Coordinated Disclosure
| |
|
Symantec pcAnywhere / IT Management Suite Product-Installation File Overwrite Local Privilege Escalation
|