|
285481
|
- |
|
hornbill
|
supportworks_itsm
|
SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote attackers to execute arbitrary SQL commands via the callref parameter.
|
CWE-89
SQL Injection
|
CVE-2013-2594
|
2024-11-21 10:52 |
2014-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285482
|
- |
|
wellintech
|
kinggraphic kingscada kingalarm\&event
|
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers to download arbitrary DLL code onto a client mach…
|
CWE-94
Code Injection
|
CVE-2013-2827
|
2024-11-21 10:52 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285483
|
- |
|
wellintech
|
kinggraphic kingscada kingalarm\&event
|
WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager console rather than on the server, which allows remote attac…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2826
|
2024-11-21 10:52 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285484
|
- |
|
sierrawireless
|
raven_x_ev-do_firmware airlink_mp_at\&t airlink_mp_at\&t_wifi airlink_mp_bell airlink_mp_bell_wifi airlink_mp_row airlink_mp_row_wifi airlink_mp_sprint airlink_mp_spri…
|
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to reprogram the firmware via a replay attack using UDP ports 17336 and 17388.
|
CWE-287
Improper Authentication
|
CVE-2013-2820
|
2024-11-21 10:52 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285485
|
- |
|
sierrawireless
|
raven_x_ev-do_firmware airlink_mp_at\&t airlink_mp_at\&t_wifi airlink_mp_bell airlink_mp_bell_wifi airlink_mp_row airlink_mp_row_wifi airlink_mp_sprint airlink_mp_spri…
|
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to install Trojan horse firmware by leveraging cleartext credentials in a crafted (1) upd…
|
CWE-255
Credentials Management
|
CVE-2013-2819
|
2024-11-21 10:52 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285486
|
- |
|
idleman
|
leed
|
Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to bypass authorization via vectors related to the (1) importForm, (2) importFeed, (3) addFavorite, or (4) removeFavorite action…
|
CWE-20
Improper Input Validation
|
CVE-2013-2629
|
2024-11-21 10:52 |
2013-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285487
|
- |
|
novatech
|
orion5_dnp_slave orionlx_dnp_slave orion5r_dnp_master orion5r_dnp_slave orionlx_dnp_master orion5_dnp_master
|
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow physically pro…
|
CWE-20
Improper Input Validation
|
CVE-2013-2822
|
2024-11-21 10:52 |
2013-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285488
|
- |
|
novatech
|
orion5_dnp_slave orionlx_dnp_slave orion5r_dnp_master orion5r_dnp_slave orionlx_dnp_master orion5_dnp_master
|
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow remote attacke…
|
CWE-20
Improper Input Validation
|
CVE-2013-2821
|
2024-11-21 10:52 |
2013-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285489
|
- |
|
idleman
|
leed
|
Multiple cross-site request forgery (CSRF) vulnerabilities in action.php in Leed (Light Feed), possibly before 1.5 Stable, allow remote attackers to hijack the authentication of administrators for un…
|
CWE-352
Origin Validation Error
|
CVE-2013-2628
|
2024-11-21 10:52 |
2013-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285490
|
- |
|
idleman
|
leed
|
SQL injection vulnerability in action.php in Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to execute arbitrary SQL commands via the id parameter in a removeFolder action.
|
CWE-89
SQL Injection
|
CVE-2013-2627
|
2024-11-21 10:52 |
2013-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|