|
283241
|
6.1 |
MEDIUM
Network
|
miwisoft
|
mijosearch
|
Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla! allows remote attackers to inject arbitrary web script or HTML via the query parameter to c…
|
CWE-79
Cross-site Scripting
|
CVE-2013-6878
|
2024-11-21 10:59 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283242
|
6.1 |
MEDIUM
Network
|
elvedia
|
flashcanvas
|
Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct cross-site scripting (XSS) attacks via the HTTP Referer header.
|
CWE-79
Cross-site Scripting
|
CVE-2013-6880
|
2024-11-21 10:59 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283243
|
8.8 |
HIGH
Network
|
d-link
|
dsl6740u_firmware
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change adm…
|
CWE-352
Origin Validation Error
|
CVE-2013-6811
|
2024-11-21 10:59 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283244
|
6.5 |
MEDIUM
Network
|
nokogiri debian redhat
|
nokogiri debian_linux openstack cloudforms_management_engine satellite subscription_asset_manager enterprise_mrg
|
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
|
CWE-776
XML Entity Expansion
|
CVE-2013-6461
|
2024-11-21 10:59 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283245
|
6.5 |
MEDIUM
Network
|
nokogiri debian redhat
|
nokogiri debian_linux openstack cloudforms_management_engine satellite subscription_asset_manager enterprise_mrg
|
Nokogiri gem 1.5.x has Denial of Service via infinite loop when parsing XML documents
|
CWE-776
XML Entity Expansion
|
CVE-2013-6460
|
2024-11-21 10:59 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283246
|
5.3 |
MEDIUM
Network
|
horde opensuse debian
|
groupware opensuse debian_linux
|
Horde Groupware Web mail 5.1.2 has CSRF with requests to change permissions
|
CWE-352
Origin Validation Error
|
CVE-2013-6365
|
2024-11-21 10:59 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283247
|
8.8 |
HIGH
Network
|
horde debian
|
groupware debian_linux
|
Horde Groupware Webmail Edition has CSRF and XSS when saving search as a virtual address book
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2013-6364
|
2024-11-21 10:59 |
2019-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283248
|
5.4 |
MEDIUM
Network
|
ibm
|
spss_modeler
|
IBM SPSS Modeler before 16 on UNIX allows remote authenticated users to bypass intended access restrictions via an SSO token. IBM X-Force ID: 89855.
|
CWE-284
Improper Access Control
|
CVE-2013-6739
|
2024-11-21 10:59 |
2018-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283249
|
7.8 |
HIGH
Local
|
s3dvt_project
|
s3dvt
|
The (1) pty_init_terminal and (2) pipe_init_terminal functions in main.c in s3dvt 0.2.2 and earlier allows local users to gain privileges by leveraging setuid permissions and usage of bash 4.3 and ea…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6876
|
2024-11-21 10:59 |
2018-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283250
|
5.4 |
MEDIUM
Network
|
redhat
|
jbpm
|
Multiple cross-site scripting (XSS) vulnerabilities in JBPM KIE Workbench 6.0.x allow remote authenticated users to inject arbitrary web script or HTML via vectors related to task name html inputs.
|
CWE-79
Cross-site Scripting
|
CVE-2013-6465
|
2024-11-21 10:59 |
2017-12-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|