|
284021
|
- |
|
alienvault
|
open_source_security_information_management
|
Multiple cross-site scripting (XSS) vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) before 4.3.0 allow remote attackers to inject arbitrary web script or HTML via th…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5300
|
2024-11-21 10:57 |
2013-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284022
|
- |
|
phpfox
|
phpfox
|
SQL injection vulnerability in PHPFox before 3.6.0 (build6) allows remote attackers to execute arbitrary SQL commands via the search[sort_by] parameter to user/browse/view_/.
|
CWE-89
SQL Injection
|
CVE-2013-5121
|
2024-11-21 10:57 |
2013-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284023
|
- |
|
phpfox
|
phpfox
|
SQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands via the search[gender] parameter to user/browse/view_/.
|
CWE-89
SQL Injection
|
CVE-2013-5120
|
2024-11-21 10:57 |
2013-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284024
|
- |
|
franz_holzinger
|
static_methods
|
Cross-site scripting (XSS) vulnerability in the Static Methods since 2007 (div2007) extension before 0.10.2 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified ve…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5100
|
2024-11-21 10:57 |
2013-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284025
|
- |
|
anchor
|
anchor_cms
|
Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Name field. NOTE: some …
|
CWE-79
Cross-site Scripting
|
CVE-2013-5099
|
2024-11-21 10:57 |
2013-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284026
|
- |
|
mikejolley
|
download_monitor
|
Cross-site scripting (XSS) vulnerability in admin/admin.php in the Download Monitor plugin before 3.3.6.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the sort par…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5098
|
2024-11-21 10:57 |
2013-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284027
|
5.4 |
MEDIUM
Network
|
otrs
|
otrs_itsm otrs
|
Cross-site scripting (XSS) vulnerability in Open Ticket Request System (OTRS) ITSM 3.0.x before 3.0.9, 3.1.x before 3.1.10, and 3.2.x before 3.2.7 allows remote authenticated users to inject arbitrar…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4718
|
2024-11-21 10:56 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284028
|
8.8 |
HIGH
Network
|
otrs
|
otrs_itsm otrs
|
Multiple SQL injection vulnerabilities in Open Ticket Request System (OTRS) Help Desk 3.0.x before 3.0.22, 3.1.x before 3.1.18, and 3.2.x before 3.2.9 allow remote authenticated users to execute arbi…
|
CWE-89
SQL Injection
|
CVE-2013-4717
|
2024-11-21 10:56 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284029
|
5.5 |
MEDIUM
Network
|
prestashop
|
prestashop
|
PrestaShop before 1.4.11 allows logout CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2013-4792
|
2024-11-21 10:56 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284030
|
5.4 |
MEDIUM
Network
|
prestashop
|
prestashop
|
PrestaShop before 1.4.11 allows Logistician, translators and other low level profiles/accounts to inject a persistent XSS vector on TinyMCE.
|
CWE-79
Cross-site Scripting
|
CVE-2013-4791
|
2024-11-21 10:56 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|