|
288681
|
- |
|
qnap
|
viostor_network_video_recorder surveillance_station_pro nas
|
cgi-bin/pingping.cgi on QNAP VioStor NVR devices with firmware 4.0.3, and in the Surveillance Station Pro component in QNAP NAS, allows remote authenticated users to execute arbitrary commands by lev…
|
CWE-94
Code Injection
|
CVE-2013-0143
|
2024-11-21 10:46 |
2013-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288682
|
- |
|
qnap
|
viostor_network_video_recorder surveillance_station_pro nas
|
QNAP VioStor NVR devices with firmware 4.0.3, and the Surveillance Station Pro component in QNAP NAS, have a hardcoded guest account, which allows remote attackers to obtain web-server login access v…
|
CWE-255
Credentials Management
|
CVE-2013-0142
|
2024-11-21 10:46 |
2013-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288683
|
- |
|
mutiny
|
mutiny_appliance mutiny_virtual_appliance mutiny
|
Multiple directory traversal vulnerabilities in the EditDocument servlet in the Frontend in Mutiny before 5.0-1.11 allow remote authenticated users to upload and execute arbitrary programs, read arbi…
|
CWE-22
Path Traversal
|
CVE-2013-0136
|
2024-11-21 10:46 |
2013-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288684
|
- |
|
cisco
|
webex
|
Cisco WebEx 4.1 on iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middl…
|
CWE-20
Improper Input Validation
|
CVE-2012-6399
|
2024-11-21 10:46 |
2013-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288685
|
- |
|
elgg
|
elgg
|
engine/lib/access.php in Elgg before 1.8.5 does not properly clear cached access lists during plugin boot, which allows remote attackers to read private entities via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6563
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288686
|
- |
|
elgg
|
elgg
|
engine/lib/users.php in Elgg before 1.8.5 does not properly specify permissions for the useradd action, which allows remote attackers to create arbitrary accounts.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6562
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288687
|
- |
|
elgg
|
elgg
|
Cross-site scripting (XSS) vulnerability in engine/lib/views.php in Elgg before 1.8.5 allows remote attackers to inject arbitrary web script or HTML via the view parameter to index.php. NOTE: some o…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6561
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288688
|
- |
|
freenac
|
freenac
|
SQL injection vulnerability in deviceadd.php in FreeNAC 3.02 allows remote attackers to execute arbitrary SQL commands via the status parameter.
|
CWE-20
Improper Input Validation
|
CVE-2012-6560
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288689
|
- |
|
freenac
|
freenac
|
Multiple cross-site scripting (XSS) vulnerabilities in FreeNAC 3.02 allow remote attackers to inject arbitrary web script or HTML via the (1) comment, (2) mac, (3) graphtype, (4) name, or (5) type pa…
|
CWE-79
Cross-site Scripting
|
CVE-2012-6559
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288690
|
- |
|
heaventools
|
pe_explorer
|
Heap-based buffer overflow in HeavenTools PE Explorer 1.99 R6 allows remote attackers to execute arbitrary code via the size value for a string in the resource section of a Portable Executable (PE) f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2012-6558
|
2024-11-21 10:46 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|