|
286011
|
- |
|
courion
|
access_risk_management_suite
|
The password reset feature in Courion Access Risk Management Suite Version 8 Update 9 allows remote authenticated users to bypass intended Internet Explorer usage restrictions and execute arbitrary c…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2747
|
2024-11-21 10:52 |
2014-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286012
|
- |
|
ibm
|
tivoli_application_dependency_discovery_manager
|
The BIRT viewer in IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.2.1.x before 7.2.1.5 allows remote authenticated users to bypass authorization checks and obtain report-administration…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2974
|
2024-11-21 10:52 |
2014-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286013
|
- |
|
e107
|
e107
|
Cross-site scripting (XSS) vulnerability in e107_plugins/content/handlers/content_preset.php in e107 before 1.0.3 allows remote attackers to inject arbitrary web script or HTML via the query string.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2750
|
2024-11-21 10:52 |
2014-01-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286014
|
- |
|
hornbill
|
supportworks_itsm
|
SQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote attackers to execute arbitrary SQL commands via the callref parameter.
|
CWE-89
SQL Injection
|
CVE-2013-2594
|
2024-11-21 10:52 |
2014-01-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286015
|
- |
|
wellintech
|
kinggraphic kingscada kingalarm\&event
|
An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers to download arbitrary DLL code onto a client mach…
|
CWE-94
Code Injection
|
CVE-2013-2827
|
2024-11-21 10:52 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286016
|
- |
|
wellintech
|
kinggraphic kingscada kingalarm\&event
|
WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager console rather than on the server, which allows remote attac…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2826
|
2024-11-21 10:52 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286017
|
- |
|
sierrawireless
|
raven_x_ev-do_firmware airlink_mp_at\&t airlink_mp_at\&t_wifi airlink_mp_bell airlink_mp_bell_wifi airlink_mp_row airlink_mp_row_wifi airlink_mp_sprint airlink_mp_spri…
|
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to reprogram the firmware via a replay attack using UDP ports 17336 and 17388.
|
CWE-287
Improper Authentication
|
CVE-2013-2820
|
2024-11-21 10:52 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286018
|
- |
|
sierrawireless
|
raven_x_ev-do_firmware airlink_mp_at\&t airlink_mp_at\&t_wifi airlink_mp_bell airlink_mp_bell_wifi airlink_mp_row airlink_mp_row_wifi airlink_mp_sprint airlink_mp_spri…
|
The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to install Trojan horse firmware by leveraging cleartext credentials in a crafted (1) upd…
|
CWE-255
Credentials Management
|
CVE-2013-2819
|
2024-11-21 10:52 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286019
|
- |
|
idleman
|
leed
|
Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to bypass authorization via vectors related to the (1) importForm, (2) importFeed, (3) addFavorite, or (4) removeFavorite action…
|
CWE-20
Improper Input Validation
|
CVE-2013-2629
|
2024-11-21 10:52 |
2013-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286020
|
- |
|
novatech
|
orion5_dnp_slave orionlx_dnp_slave orion5r_dnp_master orion5r_dnp_slave orionlx_dnp_master orion5_dnp_master
|
NovaTech Orion Substation Automation Platform OrionLX DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier and Orion5/Orion5r DNP Master 1.27.38 and DNP Slave 1.23.10 and earlier allow physically pro…
|
CWE-20
Improper Input Validation
|
CVE-2013-2822
|
2024-11-21 10:52 |
2013-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|