|
285471
|
8.8 |
HIGH
Network
|
loftek
|
nexus_543_firmware
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the Loftek Nexus 543 IP Camera allow remote attackers to hijack the authentication of unspecified victims for requests that change (1) pa…
|
CWE-352
Origin Validation Error
|
CVE-2013-3312
|
2024-11-21 10:53 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285472
|
7.5 |
HIGH
Network
|
loftek
|
nexus_543_firmware
|
Directory traversal vulnerability in the Loftek Nexus 543 IP Camera allows remote attackers to read arbitrary files via a .. (dot dot) in the URL of an HTTP GET request.
|
CWE-22
Path Traversal
|
CVE-2013-3311
|
2024-11-21 10:53 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285473
|
8.8 |
HIGH
Network
|
trendnet
|
tew-812dru_firmware
|
Undocumented TELNET service in TRENDnet TEW-812DRU when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3.
|
CWE-352
Origin Validation Error
|
CVE-2013-3366
|
2024-11-21 10:53 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285474
|
6.1 |
MEDIUM
Network
|
actiontec
|
mi424wr-gen3i_firmware
|
Unspecified Cross-site scripting (XSS) vulnerability in the Verizon FIOS Actiontec MI424WR-GEN3I router.
|
CWE-79
Cross-site Scripting
|
CVE-2013-3097
|
2024-11-21 10:53 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285475
|
9.8 |
CRITICAL
Network
|
trendnet
|
tew-691gr_firmware tew-692gr_firmware
|
Undocumented TELNET service in TRENDnet TEW-691GR and TEW-692GR when a web page named backdoor contains an HTML parameter of password and a value of j78G¬DFdg_24Mhw3.
|
CWE-287
Improper Authentication
|
CVE-2013-3367
|
2024-11-21 10:53 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285476
|
6.5 |
MEDIUM
Network
|
netgear
|
wnr3500u_firmware wnr3500l_firmware
|
NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens.
|
CWE-352
Origin Validation Error
|
CVE-2013-3516
|
2024-11-21 10:53 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285477
|
5.4 |
MEDIUM
Network
|
netgear
|
wnr3500u_firmware wnr3500l_firmware
|
Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L.
|
CWE-79
Cross-site Scripting
|
CVE-2013-3517
|
2024-11-21 10:53 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285478
|
7.8 |
HIGH
Local
|
nitropdf
|
nitro_reader nitro_pro
|
Nitro Pro 7.5.0.22 and earlier and Nitro Reader 2.5.0.36 and earlier allow remote attackers to execute arbitrary code via a crafted PDF file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-3553
|
2024-11-21 10:53 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285479
|
7.8 |
HIGH
Local
|
nitropdf
|
nitro_reader nitro_pro
|
Nitro Pro 7.5.0.29 and earlier and Nitro Reader 2.5.0.45 and earlier allow remote attackers to execute arbitrary code via a crafted PDF file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-3552
|
2024-11-21 10:53 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285480
|
- |
|
exponentcms
|
exponent_cms
|
Directory traversal vulnerability in install/popup.php in Exponent CMS before 2.2.0 RC1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
|
CWE-22
Path Traversal
|
CVE-2013-3295
|
2024-11-21 10:53 |
2014-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|