|
283231
|
5.3 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
The CentralAuth extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to obtain usernames via vectors related to writing the names to the DOM of…
|
CWE-200
Information Exposure
|
CVE-2013-6455
|
2024-11-21 10:59 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283232
|
6.1 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in MediaWiki 1.19.9 before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to inject arbitrary web script or HTML via unspecifie…
|
CWE-79
Cross-site Scripting
|
CVE-2013-6451
|
2024-11-21 10:59 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283233
|
9.8 |
CRITICAL
Network
|
google
|
android
|
Google Android prior to 4.4 has an APK Signature Security Bypass Vulnerability
|
NVD-CWE-Other
|
CVE-2013-6792
|
2024-11-21 10:59 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283234
|
4.3 |
MEDIUM
Network
|
supermicro
|
intelligent_platform_management_interface
|
Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attackers to read arbitrary files via the url_name parameter.
|
CWE-22
Path Traversal
|
CVE-2013-6785
|
2024-11-21 10:59 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283235
|
7.8 |
HIGH
Local
|
splunk
|
splunk
|
Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges
|
CWE-269
Improper Privilege Management
|
CVE-2013-6773
|
2024-11-21 10:59 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283236
|
4.3 |
MEDIUM
Network
|
splunk
|
splunk
|
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2013-6772
|
2024-11-21 10:59 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283237
|
8.8 |
HIGH
Network
|
prestashop
|
prestashop
|
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2013-6358
|
2024-11-21 10:59 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283238
|
5.4 |
MEDIUM
Network
|
pivotal_software
|
spring_framework
|
The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers …
|
CWE-79
Cross-site Scripting
|
CVE-2013-6430
|
2024-11-21 10:59 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283239
|
6.1 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform jboss_portal
|
JBossWeb Bayeux has reflected XSS
|
CWE-79
Cross-site Scripting
|
CVE-2013-6495
|
2024-11-21 10:59 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283240
|
5.3 |
MEDIUM
Network
|
miwisoft
|
mijosearch
|
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the installation pa…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2013-6879
|
2024-11-21 10:59 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|