|
287931
|
- |
|
owncloud
|
owncloud
|
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.5, 4.0.10, and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) QUERY_STRING to core/lostpassword/…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0201
|
2024-11-21 10:47 |
2014-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287932
|
- |
|
owncloud
|
owncloud
|
Cross-site request forgery (CSRF) vulnerability in apps/calendar/ajax/settings/settimezone in ownCloud before 4.0.12 allows remote attackers to hijack the authentication of users for requests that ch…
|
CWE-352
Origin Validation Error
|
CVE-2013-0301
|
2024-11-21 10:47 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287933
|
- |
|
owncloud
|
owncloud
|
Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud 4.5.x before 4.5.7 allow remote attackers to hijack the authentication of users for requests that (1) change the default view vi…
|
CWE-352
Origin Validation Error
|
CVE-2013-0300
|
2024-11-21 10:47 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287934
|
- |
|
owncloud
|
owncloud
|
Multiple cross-site request forgery (CSRF) vulnerabilities in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allow remote attackers to hijack the authentication of users for requests that (1) change t…
|
CWE-352
Origin Validation Error
|
CVE-2013-0299
|
2024-11-21 10:47 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287935
|
- |
|
owncloud
|
owncloud
|
Cross-site scripting (XSS) vulnerability in settings.php in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allows remote administrators to inject arbitrary web script or HTML via the group input field…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0307
|
2024-11-21 10:47 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287936
|
- |
|
owncloud
|
owncloud
|
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud 4.5.x before 4.5.7 allow remote attackers to inject arbitrary web script or HTML via (1) a crafted iCalendar file to the calendar appli…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0298
|
2024-11-21 10:47 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287937
|
- |
|
owncloud
|
owncloud
|
Multiple cross-site scripting (XSS) vulnerabilities in ownCloud before 4.0.12 and 4.5.x before 4.5.7 allow remote authenticated administrators to inject arbitrary web script or HTML via the (1) site_…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0297
|
2024-11-21 10:47 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287938
|
- |
|
apache
|
tomcat
|
Apache Tomcat 7.x uses world-readable permissions for the log directory and its files, which might allow local users to obtain sensitive information by reading a file. NOTE: One Tomcat distributor ha…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0346
|
2024-11-21 10:47 |
2014-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287939
|
- |
|
elgg
|
elgg
|
Cross-site scripting (XSS) vulnerability in the Twitter widget in Elgg before 1.7.17 and 1.8.x before 1.8.13 allows remote attackers to inject arbitrary web script or HTML via the params[twitter_user…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0234
|
2024-11-21 10:47 |
2014-02-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287940
|
- |
|
apache
|
ofbiz
|
Multiple cross-site scripting (XSS) vulnerabilities in widget/screen/ModelScreenWidget.java in Apache Open For Business Project (aka OFBiz) 10.04.x before 10.04.05, 11.04.01, and possibly 09.04.x all…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0177
|
2024-11-21 10:47 |
2014-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|