|
285381
|
- |
|
lockon
|
ec-cube
|
Multiple cross-site scripting (XSS) vulnerabilities in the RecommendSearch feature in the management screen in LOCKON EC-CUBE before 2.12.5 allow remote attackers to inject arbitrary web script or HT…
|
CWE-79
Cross-site Scripting
|
CVE-2013-3653
|
2024-11-21 10:54 |
2013-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285382
|
- |
|
lockon
|
ec-cube
|
Cross-site scripting (XSS) vulnerability in data/class/pages/products/LC_Page_Products_List.php in LOCKON EC-CUBE 2.11.0 through 2.12.4 allows remote attackers to inject arbitrary web script or HTML …
|
CWE-79
Cross-site Scripting
|
CVE-2013-3652
|
2024-11-21 10:54 |
2013-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285383
|
- |
|
lockon
|
ec-cube
|
Directory traversal vulnerability in LOCKON EC-CUBE 2.12.0 through 2.12.4 allows remote attackers to read arbitrary image files via vectors related to data/class/SC_CheckError.php and data/class/SC_F…
|
CWE-22
Path Traversal
|
CVE-2013-3654
|
2024-11-21 10:54 |
2013-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285384
|
- |
|
lockon
|
ec-cube
|
LOCKON EC-CUBE 2.11.2 through 2.12.4 allows remote attackers to conduct unspecified PHP code-injection attacks via a crafted string, related to data/class/SC_CheckError.php and data/class/SC_FormPara…
|
CWE-94
Code Injection
|
CVE-2013-3651
|
2024-11-21 10:54 |
2013-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285385
|
- |
|
lockon
|
ec-cube
|
Directory traversal vulnerability in the lfCheckFileName function in data/class/pages/LC_Page_ResizeImage.php in LOCKON EC-CUBE before 2.12.5 allows remote attackers to read arbitrary image files via…
|
CWE-22
Path Traversal
|
CVE-2013-3650
|
2024-11-21 10:54 |
2013-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285386
|
- |
|
ds3
|
authentication_server
|
ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter.
|
CWE-20
Improper Input Validation
|
CVE-2013-4098
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285387
|
- |
|
ds3
|
authentication_server
|
ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in a -REG-E-OPEN error …
|
CWE-22
Path Traversal
|
CVE-2013-4097
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285388
|
- |
|
ds3
|
authentication_server
|
ServerAdmin/TestTelnetConnection.jsp in DS3 Authentication Server allows remote authenticated users to execute arbitrary commands via shell metacharacters in the HOST_NAME field.
|
CWE-20
Improper Input Validation
|
CVE-2013-4096
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285389
|
- |
|
imperva
|
securesphere
|
plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to execute arbitrary commands via a task with a …
|
CWE-20
Improper Input Validation
|
CVE-2013-4095
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285390
|
- |
|
imperva
|
securesphere
|
The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) priv…
|
CWE-20
Improper Input Validation
|
CVE-2013-4094
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|