|
284321
|
- |
|
mcafee
|
epolicy_orchestrator epolicy_orchestrator_agent
|
Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee Agent (MA) 4.5 through 4.6, allow remote attackers to inject…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4883
|
2024-11-21 10:56 |
2013-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284322
|
- |
|
markus_blaschke
|
tq_seo
|
Cross-site request forgery (CSRF) vulnerability in the TEQneers SEO Enhancements (tq_seo) extension before 5.0.1 for TYPO3 allows remote attackers to hijack the authentication of unspecified victims …
|
CWE-352
Origin Validation Error
|
CVE-2013-4871
|
2024-11-21 10:56 |
2013-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284323
|
- |
|
news_search_project
|
news_search
|
SQL injection vulnerability in the News Search (news_search) extension 0.1.0 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2013-4870
|
2024-11-21 10:56 |
2013-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284324
|
- |
|
parallels
|
parallels_plesk_panel parallels_small_business_panel
|
The default configuration of Parallels Plesk Panel 9.0.x and 9.2.x on UNIX, and Small Business Panel 10.x on UNIX, has an improper ScriptAlias directive for phppath, which makes it easier for remote …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4878
|
2024-11-21 10:56 |
2013-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284325
|
- |
|
verizon
|
wireless_network_extender
|
The Verizon Wireless Network Extender SCS-26UC4 and SCS-2U01 does not use CAVE authentication, which makes it easier for remote attackers to obtain ESN and MIN values from arbitrary phones, and condu…
|
CWE-287
Improper Authentication
|
CVE-2013-4877
|
2024-11-21 10:56 |
2013-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284326
|
- |
|
verizon
|
wireless_network_extender
|
The Verizon Wireless Network Extender SCS-2U01 has a hardcoded password for the root account, which makes it easier for physically proximate attackers to obtain administrative access by leveraging a …
|
CWE-255
Credentials Management
|
CVE-2013-4876
|
2024-11-21 10:56 |
2013-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284327
|
- |
|
verizon
|
wireless_network_extender
|
The Uboot bootloader on the Verizon Wireless Network Extender SCS-2U01 allows physically proximate attackers to bypass the intended boot process and obtain a login prompt by connecting a crafted HDMI…
|
CWE-287
Improper Authentication
|
CVE-2013-4875
|
2024-11-21 10:56 |
2013-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284328
|
- |
|
verizon
|
wireless_network_extender
|
The Uboot bootloader on the Verizon Wireless Network Extender SCS-26UC4 allows physically proximate attackers to obtain root access by connecting a crafted HDMI cable and using a sys session to modif…
|
CWE-287
Improper Authentication
|
CVE-2013-4874
|
2024-11-21 10:56 |
2013-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284329
|
- |
|
yahoo
|
tumblr
|
The Yahoo! Tumblr app before 3.4.1 for iOS sends cleartext credentials, which allows remote attackers to obtain sensitive information by sniffing the network.
|
CWE-255
Credentials Management
|
CVE-2013-4873
|
2024-11-21 10:56 |
2013-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284330
|
- |
|
google
|
glass
|
Google Glass before XE6 does not properly restrict the processing of QR codes, which allows physically proximate attackers to modify the configuration or redirect users to arbitrary web sites via a c…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4872
|
2024-11-21 10:56 |
2013-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|