|
287641
|
- |
|
xmonad
|
xmonad-contrab
|
The XMonad.Hooks.DynamicLog module in xmonad-contrib before 0.11.2 allows remote attackers to execute arbitrary commands via a web page title, which activates the commands when the user clicks on the…
|
CWE-94
Code Injection
|
CVE-2013-1436
|
2024-11-21 10:49 |
2014-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287642
|
- |
|
dleviet
|
datalife_engine
|
DataLife Engine (DLE) 9.7 allows remote attackers to execute arbitrary PHP code via the catlist[] parameter to engine/preview.php, which is used in a preg_replace function call with an e modifier.
|
CWE-94
Code Injection
|
CVE-2013-1412
|
2024-11-21 10:49 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287643
|
- |
|
sensiolabs
|
symfony
|
Symfony 2.0.x before 2.0.22, 2.1.x before 2.1.7, and 2.2.x remote attackers to execute arbitrary PHP code via a serialized PHP object to the (1) Yaml::parse or (2) Yaml\Parser::parse function, a diff…
|
CWE-94
Code Injection
|
CVE-2013-1397
|
2024-11-21 10:49 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287644
|
- |
|
sensiolabs
|
symfony
|
The Yaml::parse function in Symfony 2.0.x before 2.0.22 remote attackers to execute arbitrary PHP code via a PHP file, a different vulnerability than CVE-2013-1397.
|
CWE-94
Code Injection
|
CVE-2013-1348
|
2024-11-21 10:49 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287645
|
- |
|
cisco
|
nx-os nexus_7000 nexus_7000_10-slot nexus_7000_18-slot nexus_7000_9-slot
|
Cisco NX-OS 6.1 before 6.1(5) on Nexus 7000 devices, when local authentication and multiple VDCs are enabled, allows remote authenticated users to gain privileges within an unintended VDC via crafted…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1191
|
2024-11-21 10:49 |
2014-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287646
|
- |
|
netweblogic
|
events_manager events_manager_pro
|
Multiple cross-site scripting (XSS) vulnerabilities in the Events Manager plugin before 5.3.5 and Events Manager Pro plugin before 2.2.9 for WordPress allow remote attackers to inject arbitrary web s…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1407
|
2024-11-21 10:49 |
2014-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287647
|
- |
|
webcalendar_project
|
webcalendar
|
Cross-site scripting (XSS) vulnerability in Craig Knudsen WebCalendar before 1.2.5, 1.2.6, and other versions before 1.2.7 allows remote attackers to inject arbitrary web script or HTML via the Categ…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1421
|
2024-11-21 10:49 |
2014-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287648
|
- |
|
maygion
|
ip_camera_firmware
|
Buffer overflow in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to execute arbitrary code via a long filename in a GET request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-1605
|
2024-11-21 10:49 |
2014-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287649
|
- |
|
maygion
|
ip_camera_firmware
|
Directory traversal vulnerability in MayGion IP Cameras with firmware before 2013.04.22 (05.53) allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.
|
CWE-22
Path Traversal
|
CVE-2013-1604
|
2024-11-21 10:49 |
2014-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287650
|
- |
|
wysija_newsletters_project
|
wysija_newsletters
|
Multiple SQL injection vulnerabilities in the Wysija Newsletters plugin before 2.2.1 for WordPress allow remote authenticated administrators to execute arbitrary SQL commands via the (1) search or (2…
|
CWE-89
SQL Injection
|
CVE-2013-1408
|
2024-11-21 10:49 |
2014-03-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|