<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>CVE : Nchovy &#51064;&#53552;&#45367; &#49828;&#53680; &#49468;&#53552;</title>
  <link type="text/html" href="http://nchovy.kr/security/cve" rel="alternate"/>
  <author>
    <name>NCHOVY &#51064;&#53552;&#45367; &#49828;&#53680; &#49468;&#53552;</name>
    <email>xeraph@nchovy.kr</email>
  </author>
  <entry>
    <title>CVE-2012-0979</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-0979</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-0979" rel="alternate"/>
    <content>Cross-site scripting (XSS) vulnerability in TWiki allows remote attackers to inject arbitrary web script or HTML via the organization field in a profile, involving (1) registration or (2) editing of the user.</content>
    <published>2012-02-03T02:55:01+0900</published>
    <updated>2012-02-03T02:55:01+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-0980</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-0980</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-0980" rel="alternate"/>
    <content>SQL injection vulnerability in download.php in phux Download Manager allows remote attackers to execute arbitrary SQL commands via the file parameter.</content>
    <published>2012-02-03T02:55:01+0900</published>
    <updated>2012-02-03T02:55:01+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-0448</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-0448</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-0448" rel="alternate"/>
    <content>Bugzilla 2.x and 3.x before 3.4.14, 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 does not reject non-ASCII characters in e-mail addresses of new user accounts, which makes it easier for remote authenticated users to spoof other user accounts by choosing a similar e-mail address.</content>
    <published>2012-02-03T03:55:01+0900</published>
    <updated>2012-02-03T03:55:01+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-0314</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-0314</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-0314" rel="alternate"/>
    <content>Multiple cross-site request forgery (CSRF) vulnerabilities on the eAccess Pocket WiFi (aka GP02) router before 2.00 with firmware 11.203.11.05.168 and earlier allow remote attackers to hijack the authentication of administrators for requests that (1) initialize settings or (2) reboot the device.</content>
    <published>2012-02-03T13:05:51+0900</published>
    <updated>2012-02-03T13:05:51+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-0977</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-0977</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-0977" rel="alternate"/>
    <content>Stack-based buffer overflow in jp2_x.dll in LuraWave JP2 ActiveX Control 2.1.5.5 and other versions before 2.1.5.11 allows remote attackers to execute arbitrary code via a JPEG2000 (JP2) file with a crafted Quantization Default (QCD) marker segment.</content>
    <published>2012-02-03T02:55:01+0900</published>
    <updated>2012-02-03T02:55:01+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-0975</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-0975</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-0975" rel="alternate"/>
    <content>Cross-site scripting (XSS) vulnerability in misc.php in Image Hosting Script DPI 1.0, 1.3, and earlier allows remote attackers to inject arbitrary web script or HTML via the showseries parameter.</content>
    <published>2012-02-03T02:55:00+0900</published>
    <updated>2012-02-03T02:55:00+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-0982</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-0982</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-0982" rel="alternate"/>
    <content>SQL injection vulnerability in search.php in Vastal I-Tech Agent Zone (aka The Real Estate Script) allows remote attackers to execute arbitrary SQL commands via the price_from parameter.</content>
    <published>2012-02-03T02:55:01+0900</published>
    <updated>2012-02-03T02:55:01+0900</updated>
  </entry>
  <entry>
    <title>CVE-2012-0440</title>
    <author>
      <name>National Vulnerability Database</name>
    </author>
    <id>http://nchovy.kr/security/cve/CVE-2012-0440</id>
    <link type="text/html" href="http://nchovy.kr/security/cve/CVE-2012-0440" rel="alternate"/>
    <content>Cross-site request forgery (CSRF) vulnerability in jsonrpc.cgi in Bugzilla 3.5.x and 3.6.x before 3.6.8, 3.7.x and 4.0.x before 4.0.4, and 4.1.x and 4.2.x before 4.2rc2 allows remote attackers to hijack the authentication of arbitrary users for requests that use the JSON-RPC API.</content>
    <published>2012-02-03T03:55:01+0900</published>
    <updated>2012-02-03T03:55:01+0900</updated>
  </entry>
</feed>

