Advantech WebAccess HMI/SCADA software version 7.0-2012.12.05 suffers from a persistent cross site scripting vulnerability.
c464b8149b11c22b146cd1282f4bc0fb07c6fa07603793bf344a5c29515c7e5f
NetArt Media Pharmacy System version 2.0 suffers from cross site scripting and remote SQL injection vulnerabilities.
571ede9e0f61702e459089e92ef605c1088c80b80d2c48abf07296d09534e227
NetArt Media iBoutique version 4.0 suffers from a remote SQL injection vulnerability.
63f73c7bb565caa378994bb034b6965af92076cb74824b72cfb4912c073f4eb0
Oxide Webserver versions 2.0.4 and below suffer from a remote denial of service vulnerability.
78053e16329204d000b42f631dfb570dbbbb076108666340fe38090874ae6db5
ArticleSetup versions 1.11 and below suffer from cross site scripting and remote SQL injection vulnerabilities.
9989e178ae23e232b3197892da9d4f97be442d52ccc77c18923483a98701abc4
Apache Struts versions 1.3.10, 2.0.14 and 2.2.3 suffer from multiple cross site scripting vulnerabilities.
d9fa78ab565ffc78f9b758171aa45c73f075a712e2b675fb27d4d85d6afd0004
Xataface WebAuction versions 0.3.6 and below and Xataface Librarian DB versions 0.2 and below suffer from cross site scripting, local file inclusion, and remote SQL injection vulnerabilities.
eeb1be34f9b3ea62cad720ef286c45c943798050461a867a2c199ec66f0143b6
CiscoKits TFTP server suffers from a directory traversal vulnerability. Proof of concept exploit is attached to the bottom of this advisory.
161191def09b6edbb36740f1d85f6955252011a6a6ee190d223c5da1d0349b48
appRain versions 0.1.3 and 0.1.4-Alpha for both the Quick Start and Core editions suffer from multiple cross site scripting vulnerabilities.
52dd436444b837a85cbfd4a287fbb817919e848eaff7f9d393464836a3a9b5b2
AT-TFTP Server version 1.18 suffers from a remote denial of service vulnerability. Proof of concept exploit is included.
072356984ca8faefce1723f3102ee7b8a3127843c984c8180efac28c181306ae
AR Web Content Manager (AWCM) version 2.2 suffers from a cross site scripting vulnerability.
e5bda51443c337b7abb8f77ee5bdc9061e3221dad52ec0d5738aee55bda5ce80
Pecio CMS version 2.0.5 suffers from a cross site scripting vulnerability.
05dc4479ffde12054111c5b44dadfafa2c5120d85eb6482e1494df7de92e8cf7