|
284361
|
- |
|
js-yaml_project
|
js-yaml
|
The JS-YAML module before 2.0.5 for Node.js parses input without properly considering the unsafe !!js/function tag, which allows remote attackers to execute arbitrary code via a crafted string that t…
|
CWE-20
Improper Input Validation
|
CVE-2013-4660
|
2024-11-21 10:56 |
2013-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284362
|
- |
|
3ds
|
push2rss_3ds
|
SQL injection vulnerability in the RSS feed from records extension 1.0.0 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2013-4721
|
2024-11-21 10:56 |
2013-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284363
|
- |
|
webempoweredchurch
|
wec_discussion
|
SQL injection vulnerability in the WEC Discussion Forum extension before 2.1.2 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2013-4720
|
2024-11-21 10:56 |
2013-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284364
|
- |
|
lina_wolf
|
seo_pack_for_tt_news
|
SQL injection vulnerability in the SEO Pack for tt_news extension before 1.3.3 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2013-4719
|
2024-11-21 10:56 |
2013-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284365
|
- |
|
christophe_balisky
|
meta_feedit
|
SQL injection vulnerability in the meta_feedit extension 0.1.10 and earlier for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2013-4683
|
2024-11-21 10:56 |
2013-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284366
|
- |
|
bas_van_beek
|
multishop
|
SQL injection vulnerability in the Multishop extension before 2.0.39 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2013-4682
|
2024-11-21 10:56 |
2013-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284367
|
- |
|
michael_staatz
|
sofortueberweisung2commerce
|
SQL injection vulnerability in the sofortueberweisung2commerce extension before 2.0.1 for TYPO3 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2013-4681
|
2024-11-21 10:56 |
2013-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284368
|
- |
|
urs_maag
|
maag_form_captcha
|
Open redirect vulnerability in Maag Form Captcha extension 2.0.0 and earlier for TYPO3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified ve…
|
NVD-CWE-noinfo
|
CVE-2013-4680
|
2024-11-21 10:56 |
2013-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284369
|
- |
|
fortinet
|
forticlient forticlient_lite forticlient_ssl_vpn
|
FortiClient before 4.3.5.472 on Windows, before 4.0.3.134 on Mac OS X, and before 4.0 on Android; FortiClient Lite before 4.3.4.461 on Windows; FortiClient Lite 2.0 through 2.0.0223 on Android; and F…
|
CWE-255 CWE-310
Credentials Management Cryptographic Issues
|
CVE-2013-4669
|
2024-11-21 10:56 |
2013-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284370
|
5.5 |
MEDIUM
Local
|
redhat
|
openshift
|
In Red Hat Openshift 1, weak default permissions are applied to the /etc/openshift/server_priv.pem file on the broker server, which could allow users with local access to the broker to read this file.
|
-
|
CVE-2013-4281
|
2024-11-21 10:55 |
2022-10-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|