|
284731
|
- |
|
apache
|
mod_dontdothat subversion
|
The is_this_legal function in mod_dontdothat for Apache Subversion 1.4.0 through 1.7.13 and 1.8.0 through 1.8.4 allows remote attackers to bypass intended access restrictions and possibly cause a den…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4505
|
2024-11-21 10:55 |
2013-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284732
|
- |
|
supmua
|
sup
|
lib/sup/message_chunks.rb in Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the content_type of an email attachment.
|
CWE-94
Code Injection
|
CVE-2013-4479
|
2024-11-21 10:55 |
2013-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284733
|
- |
|
supmua
|
sup
|
Sup before 0.13.2.1 and 0.14.x before 0.14.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the filename of an email attachment.
|
CWE-94
Code Injection
|
CVE-2013-4478
|
2024-11-21 10:55 |
2013-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284734
|
- |
|
steven_jones
|
context
|
The _json_decode function in plugins/context_reaction_block.inc in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal, when using a version of PHP that does not support t…
|
CWE-94
Code Injection
|
CVE-2013-4446
|
2024-11-21 10:55 |
2013-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284735
|
- |
|
steven_jones
|
context
|
The json rendering functionality in the Context module 6.x-2.x before 6.x-3.2 and 7.x-3.x before 7.x-3.0 for Drupal uses Drupal's token scheme to restrict access to blocks, which makes it easier for …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4445
|
2024-11-21 10:55 |
2013-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284736
|
- |
|
apache
|
roller
|
Certain getText methods in the ActionSupport controller in Apache Roller before 5.0.2 allow remote attackers to execute arbitrary OGNL expressions via the first or second parameter, as demonstrated b…
|
CWE-94
Code Injection
|
CVE-2013-4212
|
2024-11-21 10:55 |
2013-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284737
|
- |
|
apache
|
roller
|
Multiple cross-site scripting (XSS) vulnerabilities in Apache Roller before 5.0.2 allow remote attackers to inject arbitrary web script or HTML via vectors related to the search results in the (1) RS…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4171
|
2024-11-21 10:55 |
2013-12-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284738
|
- |
|
i18n_project
|
i18n
|
Cross-site scripting (XSS) vulnerability in exceptions.rb in the i18n gem before 0.6.6 for Ruby allows remote attackers to inject arbitrary web script or HTML via a crafted I18n::MissingTranslationDa…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4492
|
2024-11-21 10:55 |
2013-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284739
|
- |
|
rubyonrails
|
rails ruby_on_rails
|
Cross-site scripting (XSS) vulnerability in actionpack/lib/action_view/helpers/translation_helper.rb in the internationalization component in Ruby on Rails 3.x before 3.2.16 and 4.x before 4.0.2 allo…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4491
|
2024-11-21 10:55 |
2013-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284740
|
- |
|
jahia
|
jahia_xcm
|
Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to inject arbitrary web script or HTML via (1) the site parameter to engines/manager.js…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4624
|
2024-11-21 10:55 |
2013-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|