|
283021
|
- |
|
php-fusion
|
php-fusion
|
SQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to execute arbitrary SQL commands via the user ID in a user cookie…
|
CWE-89
SQL Injection
|
CVE-2013-7375
|
2024-11-21 11:00 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283022
|
- |
|
livezilla
|
livezilla
|
The setCookieValue function in _lib/functions.global.inc.php in LiveZilla before 5.1.2.1 allows remote attackers to execute arbitrary PHP code via a serialized PHP object in a cookie.
|
CWE-94
Code Injection
|
CVE-2013-7034
|
2024-11-21 11:00 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283023
|
- |
|
livezilla
|
livezilla
|
Multiple cross-site scripting (XSS) vulnerabilities in LiveZilla before 5.1.2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) full name field, (2) company field, or (3) fi…
|
CWE-79
Cross-site Scripting
|
CVE-2013-7003
|
2024-11-21 11:00 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283024
|
- |
|
plone
|
plone
|
Products/CMFPlone/CatalogTool.py in Plone 3.3 through 4.3.2 allows remote administrators to bypass restrictions and obtain sensitive information via an unspecified search API.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7061
|
2024-11-21 11:00 |
2014-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283025
|
- |
|
plone
|
plone
|
Products/CMFPlone/FactoryTool.py in Plone 3.3 through 4.3.2 allows remote attackers to obtain the installation path via vectors related to a file object for unspecified documentation which is initial…
|
CWE-200
Information Exposure
|
CVE-2013-7060
|
2024-11-21 11:00 |
2014-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283026
|
- |
|
transifex
|
transifex
|
Transifex command-line client before 0.10 does not validate X.509 certificates for data transfer connections, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary cer…
|
CWE-20
Improper Input Validation
|
CVE-2013-7110
|
2024-11-21 11:00 |
2014-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283027
|
- |
|
canonical
|
ubuntu_linux
|
The Ubuntu Date and Time Indicator (aka indicator-datetime) 13.10.0+13.10.x before 13.10.0+13.10.20131023.2-0ubuntu1.1 does not properly restrict access to Evolution, which allows local users to bypa…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7374
|
2024-11-21 11:00 |
2014-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283028
|
- |
|
fortinet
|
fortiauthenticator
|
FortiGuard FortiAuthenticator before 3.0 allows remote administrators to gain privileges via the command line interface.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6990
|
2024-11-21 11:00 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283029
|
- |
|
google
|
android
|
Android before 4.4 does not properly arrange for seeding of the OpenSSL PRNG, which makes it easier for attackers to defeat cryptographic protection mechanisms by leveraging use of the PRNG within mu…
|
CWE-200
Information Exposure
|
CVE-2013-7373
|
2024-11-21 11:00 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283030
|
- |
|
google apache
|
android harmony
|
The engineNextBytes function in classlib/modules/security/src/main/java/common/org/apache/harmony/security/provider/crypto/SHA1PRNG_SecureRandomImpl.java in the SecureRandom implementation in Apache …
|
CWE-310
Cryptographic Issues
|
CVE-2013-7372
|
2024-11-21 11:00 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|