Browse Database

Browsing Vulnerabilities Disclosed in December of 2011

<< Back to Browse
OSVDB IDDisclosure DateTitle
78104 2011-12-31 Whois Search Plugin for WordPress index.php domain Parameter XSS
78718 2011-12-31 Bugzilla UTF-8 Encoded Character Email Address Handling Arbitrary User Spoofing
78096 2011-12-31 TheCartPress Plugin for WordPress admin/OptionsPostsList.php tcp_name_post_1 Parameter XSS
78139 2011-12-31 Mozilla Firefox Drag and Drop Handling XSS Weakness
78231 2011-12-31 dl Download Ticket Service Internal Authorization Header Parsing Authentication Bypass
78222 2011-12-31 ZNC bouncedcc Module modules/bouncedcc.cpp CBounceDCCMod::OnPrivCTCP() Function DCC Command Parsing Remote DoS
78596 2011-12-31 Kaixin001 (com.kaixin001.activity) Application for Android Unspecified User Data Manipulation
78898 2011-12-31 OCaml Hash Collision CPU Consumption Remote DoS
78110 2011-12-30 MaraDNS Hash Collision Form Parameter Parsing Remote DoS
78679 2011-12-30 RESTEasy XML Entity Reference Parsing Remote Information Disclosure
81781 2011-12-30 Cisco Unified MeetingPlace Unspecified Traversal Folder Enumeration
82506 2011-12-30 DedeCMS list.php id Parameter SQL Injection
82507 2011-12-30 DedeCMS members.php id Parameter SQL Injection
82508 2011-12-30 DedeCMS book.php id Parameter SQL Injection
78054 2011-12-30 Microsoft .NET Framework Forms Authentication Return URL Handling Arbitrary Site Redirect
78055 2011-12-30 Microsoft .NET Framework ASP.NET Username Parsing Authentication Bypass
78686 2011-12-30 Kayako SupportSuite Tickets Module staff/index.php title Parameter XSS
81783 2011-12-30 Cisco Unified MeetingPlace MP Web Unspecified XSS
78117 2011-12-30 Jetty Hash Collision Form Parameter Parsing Remote DoS
78115 2011-12-30 PHP Hash Collision Form Parameter Parsing Remote DoS
78682 2011-12-30 Kayako SupportSuite Troubleshooter Module staff/index.php description Parameter XSS
78683 2011-12-30 Kayako SupportSuite Downloads Module staff/index.php title Parameter XSS
78684 2011-12-30 Kayako SupportSuite Teamwork Module staff/index.php Multiple Parameter XSS
78685 2011-12-30 Kayako SupportSuite Livesupport Module staff/index.php Multiple Parameter XSS
81782 2011-12-30 Cisco Unified MeetingPlace Account Page Unspecified XSS
84170 2011-12-30 WebKit Inline Positioned Element Handling Use-after-free Issue
78069 2011-12-29 Akiva WebBoard /WB/Default.asp name Parameter SQL Injection Authentication Bypass
78056 2011-12-29 Microsoft .NET Framework Forms Authentication Sliding Expiry Cached Content Parsing Remote Code Execution
78681 2011-12-29 Kayako SupportSuite News Module staff/index.php subject Parameter XSS
78280 2011-12-29 MaraDNS Hash Collision Zone File Record Parsing Local DoS
78460 2011-12-29 Kayako SupportSuite staff/index.php resultdata Parameter XSS
78461 2011-12-29 Kayako SupportSuite Template Editing PHP Code Execution
78068 2011-12-29 Neturf eCommerce Shopping Cart search.php SearchFor Parameter XSS
78114 2011-12-29 Oracle GlassFish Server Hash Collision Form Parameter Parsing Remote DoS
78080 2011-12-29 Blog Module for DiY-CMS list.php Multiple Parameter SQL Injection
78081 2011-12-29 Blog Module for DiY-CMS index.php Multiple Parameter SQL Injection
78082 2011-12-29 Blog Module for DiY-CMS main_index.php Multiple Parameter SQL Injection
78083 2011-12-29 Blog Module for DiY-CMS viewpost.php Multiple Parameter SQL Injection
78459 2011-12-29 Kayako SupportSuite staff/index.php Multiple Parameter Empty Value Path Disclosure
78462 2011-12-29 Kayako SupportSuite LiveSupport Module Subject Parameter XSS

The database information may change without any notice. Use of the information constitutes acceptance for use in an AS IS condition, and there are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. In no event shall the copyright holder or distributor (OSVDB or OSF) be held liable for any damages whatsoever arising out of or in connection with the use or spread of this information.

© Copyright 2002 - 2013 Open Source Vulnerability Database (OSVDB), All Rights Reserved.
Privacy Statement - Terms of Use