CVE-2012-4248
https://notcve.org/view.php?id=CVE-2012-4248
The Amazon Kindle Touch before 5.1.2 does not properly restrict access to the libkindleplugin.so NPAPI plugin interface, which might allow remote attackers to have an unspecified impact via vectors involving the (1) dev.log, (2) lipc.set, (3) lipc.get, or (4) todo.scheduleItems method, a different vulnerability than CVE-2012-4249. La tableta Amazon Kindle Touch anterior a v5.1.2 no restringe adecuadamente el acceso a la interfaz del plugin libkindleplugin.so NPAPI lo que podría permitir a atacantes remotos obtener acceso a través de vectores que incluyen (1) dev.log, (2) lipc.set, (3) lipc.get, o (4) todo.scheduleItems method, una vulnerabilidad diferente que CVE-2012-4249. • http://www.kb.cert.org/vuls/id/122656 http://www.kb.cert.org/vuls/id/MORO-8WKGBN http://www.mobileread.com/forums/showthread.php?s=c7953cc553a4aaa36e880b25aa1a6bf6&t=175368 • CWE-264: Permissions, Privileges, and Access Controls •
CVE-2012-4249
https://notcve.org/view.php?id=CVE-2012-4249
The Amazon Lab126 com.lab126.system sendEvent implementation on the Kindle Touch before 5.1.2 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a string, as demonstrated by using lipc-set-prop to set an LIPC property, a different vulnerability than CVE-2012-4248. La implementación de Amazon Lab126 com.lab126.system sendEvent en la pantalla táctil de Kindle antes de v5.1.2 permite ejecutar comandos de su elección vía metacaracteres ocultos en una cadena a atacantes dependientes del contexto, tal y como se ha demostrado mediante el uso de CFIG-set-prop para establecer una propiedad CFIG. Se trata de un vulnerabilidad diferente a CVE-2012-4248. • http://www.kb.cert.org/vuls/id/122656 http://www.kb.cert.org/vuls/id/MORO-8WKGBN http://www.mobileread.com/forums/showthread.php?s=c7953cc553a4aaa36e880b25aa1a6bf6&t=175368 • CWE-94: Improper Control of Generation of Code ('Code Injection') •
CVE-2005-3908 – GhostScripter Amazon Shop 5.0 - 'search.php' SQL Injection
https://notcve.org/view.php?id=CVE-2005-3908
Cross-site scripting (XSS) vulnerability in search.php in GhostScripter Amazon Shop 5.0.0, and other versions before 5.0.2, allows remote attackers to inject web script or HTML via the query parameter. • https://www.exploit-db.com/exploits/26653 http://pridels0.blogspot.com/2005/11/amazon-shop-500-xss-vuln.html http://secunia.com/advisories/17750 http://www.attrition.org/pipermail/vim/2007-May/001603.html http://www.osvdb.org/21371 http://www.securityfocus.com/bid/15634 http://www.vupen.com/english/advisories/2005/2630 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •