|
290251
|
9.8 |
CRITICAL
Network
|
milboj
|
flash_tool
|
The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.
|
CWE-77
Command Injection
|
CVE-2013-2513
|
2024-11-21 10:51 |
2023-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290252
|
9.8 |
CRITICAL
Network
|
ftpd_project
|
ftpd
|
The ftpd gem 0.2.1 for Ruby allows remote attackers to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command argument within FTP protocol traffic.
|
CWE-78
OS Command
|
CVE-2013-2512
|
2024-11-21 10:51 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290253
|
7.8 |
HIGH
Local
|
zpanel_project
|
zpanel
|
ZPanel through 10.1.0 has Remote Command Execution
|
NVD-CWE-noinfo
|
CVE-2013-2097
|
2024-11-21 10:51 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290254
|
5.5 |
MEDIUM
Local
|
kde
|
paste_applet
|
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent att…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2013-2213
|
2024-11-21 10:51 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290255
|
8.4 |
HIGH
Local
|
kde
|
paste_applet
|
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass…
|
CWE-287
Improper Authentication
|
CVE-2013-2120
|
2024-11-21 10:51 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290256
|
8.8 |
HIGH
Network
|
undolog
|
wp_cleanfix
|
WordPress plugin wp-cleanfix has Remote Code Execution
|
CWE-352
Origin Validation Error
|
CVE-2013-2109
|
2024-11-21 10:51 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290257
|
5.4 |
MEDIUM
Network
|
undolog
|
cleanfix
|
WordPress WP Cleanfix Plugin 2.4.4 has CSRF
|
CWE-352
Origin Validation Error
|
CVE-2013-2108
|
2024-11-21 10:51 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290258
|
6.1 |
MEDIUM
Network
|
viewgit_project
|
viewgit
|
Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a (1) tag name to the Shortlog table in templates/…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2294
|
2024-11-21 10:51 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290259
|
9.8 |
CRITICAL
Network
|
login_security_project
|
login_security
|
The Login Security module 6.x-1.x before 6.x-1.3 and 7.x-1.x before 7.x-1.3 for Drupal allows attackers to bypass intended restrictions via a crafted username.
|
CWE-863
Incorrect Authorization
|
CVE-2013-2198
|
2024-11-21 10:51 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290260
|
7.5 |
HIGH
Network
|
foscam
|
fi8620_firmware
|
An Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /log/ directories, which could let a malicious user obtain sensitive information.
|
CWE-863
Incorrect Authorization
|
CVE-2013-2574
|
2024-11-21 10:51 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|