|
284991
|
5.4 |
MEDIUM
Network
|
projectpier
|
projectpier
|
ProjectPier 0.8.8 has a Remote Information Disclosure Weakness because of the lack of the HttpOnly cookie flag
|
CWE-79
Cross-site Scripting
|
CVE-2013-3636
|
2024-11-21 10:54 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284992
|
5.4 |
MEDIUM
Network
|
projectpier
|
projectpier
|
ProjectPier 0.8.8 has stored XSS
|
CWE-79
Cross-site Scripting
|
CVE-2013-3635
|
2024-11-21 10:54 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284993
|
8.8 |
HIGH
Network
|
ispconfig
|
ispconfig
|
ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution
|
NVD-CWE-Other
|
CVE-2013-3629
|
2024-11-21 10:54 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284994
|
8.8 |
HIGH
Network
|
zabbix
|
zabbix
|
Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability
|
CWE-74
Injection
|
CVE-2013-3628
|
2024-11-21 10:54 |
2020-02-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284995
|
8.8 |
HIGH
Network
|
boonex
|
dolphin
|
SQL injection vulnerability in Boonex Dolphin before 7.1.3 allows remote authenticated users to execute arbitrary SQL commands via the 'pathes' parameter in 'categories.php'.
|
CWE-89
SQL Injection
|
CVE-2013-3638
|
2024-11-21 10:54 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284996
|
9.9 |
CRITICAL
Network
|
easytimestudio
|
easy_file_manager
|
Easytime Studio Easy File Manager 1.1 has a HTTP request security bypass
|
CWE-862
Missing Authorization
|
CVE-2013-3960
|
2024-11-21 10:54 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284997
|
9.8 |
CRITICAL
Network
|
xnview
|
xnview
|
Xjp2.dll in XnView before 2.13 allows remote attackers to execute arbitrary code via (1) the Csiz parameter in a SIZ marker, which triggers an incorrect memory allocation, or (2) the lqcd field in a …
|
CWE-787
Out-of-bounds Write
|
CVE-2013-3941
|
2024-11-21 10:54 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284998
|
7.8 |
HIGH
Local
|
xnview
|
xnview
|
xnview.exe in XnView before 2.13 does not properly handle RLE strip lengths during processing of RGB files, which allows remote attackers to execute arbitrary code via the RLE strip size field in a R…
|
CWE-787
Out-of-bounds Write
|
CVE-2013-3939
|
2024-11-21 10:54 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284999
|
7.8 |
HIGH
Local
|
xnview
|
xnview
|
Heap-based buffer overflow in xnview.exe in XnView before 2.13 allows remote attackers to execute arbitrary code via the biBitCount field in a BMP file.
|
CWE-787
Out-of-bounds Write
|
CVE-2013-3937
|
2024-11-21 10:54 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285000
|
8.8 |
HIGH
Network
|
jomres
|
jomres
|
SQL injection vulnerability in the Jomres (com_jomres) component before 7.3.1 for Joomla! allows remote authenticated users with the "Business Manager" permission to execute arbitrary SQL commands vi…
|
CWE-89
SQL Injection
|
CVE-2013-3932
|
2024-11-21 10:54 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|