|
283581
|
- |
|
debian
|
phpbb3
|
Phpbb3 before 3.0.11-4 for Debian GNU/Linux uses world-writable permissions for cache files, which allows local users to modify the file contents via standard filesystem write operations.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5724
|
2024-11-21 10:58 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283582
|
- |
|
sap
|
netweaver
|
SQL injection vulnerability in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, related to "ABAD0_DELETE_DERIVATION_TABLE."
|
CWE-89
SQL Injection
|
CVE-2013-5723
|
2024-11-21 10:58 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283583
|
- |
|
wordpress
|
wordpress
|
The default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote authenticated users to conduct cross-site scripting (XSS) at…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5739
|
2024-11-21 10:58 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283584
|
- |
|
wordpress
|
wordpress
|
The get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability for uploads of .htm and .html files, which might make it eas…
|
CWE-20
Improper Input Validation
|
CVE-2013-5738
|
2024-11-21 10:58 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283585
|
- |
|
gomlab
|
gom_player
|
Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file.
|
CWE-20
Improper Input Validation
|
CVE-2013-5716
|
2024-11-21 10:58 |
2013-09-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283586
|
4.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Mozilla Firefox before 25 allows modification of anonymous content of pluginProblem.xml binding
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2013-5594
|
2024-11-21 10:57 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283587
|
7.5 |
HIGH
Network
|
aicorporation
|
risknet_acquirer
|
RiskNet Acquirer before hotfix 6.0 b7+ADHOC-443 ApplicationServiceBean contains a service information disclosure.
|
CWE-200
Information Exposure
|
CVE-2013-5687
|
2024-11-21 10:57 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283588
|
6.1 |
MEDIUM
Network
|
easyxdm
|
easyxdm
|
Cross-site Scripting (XSS) in EasyXDM before 2.4.18 allows remote attackers to inject arbitrary web script or html via the easyxdm.swf file.
|
CWE-79
Cross-site Scripting
|
CVE-2013-5212
|
2024-11-21 10:57 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283589
|
8.8 |
HIGH
Network
|
python-mode_project
|
python-mode
|
A Code Execution vulnerability exists in select.py when using python-mode 2012-12-19.
|
CWE-20
Improper Input Validation
|
CVE-2013-5106
|
2024-11-21 10:57 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283590
|
7.8 |
HIGH
Local
|
ammyy
|
ammyy_admin
|
Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that ext…
|
CWE-287
Improper Authentication
|
CVE-2013-5582
|
2024-11-21 10:57 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|