|
283101
|
- |
|
wpdownloadmanager
|
wordpress_download_manager
|
Cross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the title field.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7319
|
2024-11-21 11:00 |
2014-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283102
|
- |
|
seowonintech
|
swc-9100
|
cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) via a default_reboot action or (2) reset all configuration values via a factory_…
|
CWE-287
Improper Authentication
|
CVE-2013-7183
|
2024-11-21 11:00 |
2014-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283103
|
- |
|
fortinet
|
fortios
|
Cross-site scripting (XSS) vulnerability in firewall/schedule/recurrdlg in Fortinet FortiOS 5.0.5 allows remote attackers to inject arbitrary web script or HTML via the mkey parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7182
|
2024-11-21 11:00 |
2014-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283104
|
- |
|
fortinet
|
fortiweb
|
Cross-site scripting (XSS) vulnerability in user/ldap_user/add in Fortinet FortiOS 5.0.3 allows remote attackers to inject arbitrary web script or HTML via the filter parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7181
|
2024-11-21 11:00 |
2014-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283105
|
- |
|
seowonintech
|
swc-9100
|
The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute arbitrary commands via shell metacharacters in the ping_ipaddr parameter.
|
CWE-20
Improper Input Validation
|
CVE-2013-7179
|
2024-11-21 11:00 |
2014-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283106
|
- |
|
craig_drummond
|
cantata
|
Cantata before 1.2.2 does not restrict access to files in the play queue, which allows remote attackers to obtain sensitive information by reading the songs in the queue.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7301
|
2024-11-21 11:00 |
2014-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283107
|
- |
|
craig_drummond
|
cantata
|
Absolute path traversal vulnerability in cantata before 1.2.2 allows local users to read arbitrary files via a full pathname in a request to the internal httpd server. NOTE: this vulnerability can b…
|
CWE-22
Path Traversal
|
CVE-2013-7300
|
2024-11-21 11:00 |
2014-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283108
|
- |
|
fail2ban
|
fail2ban
|
config/filter.d/cyrus-imap.conf in the cyrus-imap filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary IP address via a crafted e-mail address that matches…
|
CWE-20
Improper Input Validation
|
CVE-2013-7177
|
2024-11-21 11:00 |
2014-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283109
|
- |
|
fail2ban
|
fail2ban
|
config/filter.d/postfix.conf in the postfix filter in Fail2ban before 0.8.11 allows remote attackers to trigger the blocking of an arbitrary IP address via a crafted e-mail address that matches an im…
|
CWE-20
Improper Input Validation
|
CVE-2013-7176
|
2024-11-21 11:00 |
2014-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283110
|
- |
|
spip
|
spip
|
Multiple cross-site scripting (XSS) vulnerabilities in (1) squelettes-dist/formulaires/inscription.php and (2) prive/forms/editer_auteur.php in SPIP before 2.1.25 and 3.0.x before 3.0.13 allow remote…
|
CWE-79
Cross-site Scripting
|
CVE-2013-7303
|
2024-11-21 11:00 |
2014-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|