|
285371
|
- |
|
knowledgeview
|
knowledgeview_editorial_and_management_application
|
Cross-site scripting (XSS) vulnerability in the KnowledgeView Editorial and Management application allows remote attackers to inject arbitrary web script or HTML via the username parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-3616
|
2024-11-21 10:53 |
2013-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285372
|
- |
|
dell
|
idrac6_firmware idrac6_monolithic idrac7_firmware idrac7
|
Cross-site scripting (XSS) vulnerability in the login page in the Administrative Web Interface on Dell iDRAC6 monolithic devices with firmware before 1.96 and iDRAC7 devices with firmware before 1.46…
|
CWE-79
Cross-site Scripting
|
CVE-2013-3589
|
2024-11-21 10:53 |
2013-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285373
|
- |
|
cisco
|
prime_central_for_hosted_collaboration_solution_assurance
|
The web framework in Cisco Prime Central for Hosted Collaboration Solution (HCS) Assurance before 9.1.1 does not properly determine the existence of an authenticated session, which allows remote atta…
|
CWE-287
Improper Authentication
|
CVE-2013-3473
|
2024-11-21 10:53 |
2013-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285374
|
- |
|
dahuasecurity
|
dvr2104h dvr0404hd-a dvr1604hd-l dvr2104hc dvr5216a dvr5104he dvr3204lf-al dvr5204a dvr3204hf-s dvr0404hd-s dvr0804 dvr5104h dvr5804 dvr2116h dvr2404lf-al
|
Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force attack.
|
CWE-255
Credentials Management
|
CVE-2013-3615
|
2024-11-21 10:53 |
2013-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285375
|
- |
|
dahuasecurity
|
dvr2104h dvr0404hd-a dvr1604hd-l dvr2104hc dvr5216a dvr5104he dvr3204lf-al dvr5204a dvr3204hf-s dvr0404hd-s dvr0804 dvr5104h dvr5804 dvr2116h dvr2404lf-al
|
Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port.
|
CWE-287
Improper Authentication
|
CVE-2013-3613
|
2024-11-21 10:53 |
2013-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285376
|
- |
|
dahuasecurity
|
dvr2104h dvr0404hd-a dvr1604hd-l dvr2104hc dvr5216a dvr5104he dvr3204lf-al dvr5204a dvr3204hf-s dvr0404hd-s dvr0804 dvr5104h dvr5804 dvr2116h dvr2404lf-al
|
Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-force attack.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3614
|
2024-11-21 10:53 |
2013-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285377
|
- |
|
dahuasecurity
|
dvr2104h dvr0404hd-a dvr1604hd-l dvr2104hc dvr5216a dvr5104he dvr3204lf-al dvr5204a dvr3204hf-s dvr0404hd-s dvr0804 dvr5104h dvr5804 dvr2116h dvr2404lf-al
|
Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via autho…
|
CWE-255
Credentials Management
|
CVE-2013-3612
|
2024-11-21 10:53 |
2013-09-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285378
|
- |
|
cisco
|
digital_media_manager
|
Open redirect vulnerability in the login page in Cisco Digital Media Manager (DMM) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vector…
|
CWE-20
Improper Input Validation
|
CVE-2013-3446
|
2024-11-21 10:53 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285379
|
- |
|
adobe
|
flash_player air air_sdk
|
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Andro…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-3363
|
2024-11-21 10:53 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285380
|
- |
|
adobe
|
flash_player air air_sdk
|
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Andro…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-3362
|
2024-11-21 10:53 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|