|
285181
|
- |
|
x2engine
|
x2crm
|
Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the model parameter to index.php/admin/editor.
|
CWE-79
Cross-site Scripting
|
CVE-2013-5693
|
2024-11-21 10:57 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285182
|
- |
|
x2engine
|
x2crm
|
Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to inde…
|
CWE-22
Path Traversal
|
CVE-2013-5692
|
2024-11-21 10:57 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285183
|
- |
|
simone_tellini
|
mod_accounting
|
SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header.
|
CWE-89
SQL Injection
|
CVE-2013-5697
|
2024-11-21 10:57 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285184
|
- |
|
redhat
|
libvirt
|
The virBitmapParse function in util/virbitmap.c in libvirt before 1.1.2 allows context-dependent attackers to cause a denial of service (out-of-bounds read and crash) via a crafted bitmap, as demonst…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-5651
|
2024-11-21 10:57 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285185
|
- |
|
owasp
|
enterprise_security_api
|
The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serializ…
|
CWE-310
Cryptographic Issues
|
CVE-2013-5679
|
2024-11-21 10:57 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285186
|
- |
|
cisco
|
identity_services_engine_software
|
Cross-site scripting (XSS) vulnerability in an administration page in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via an unspecified parameter,…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5505
|
2024-11-21 10:57 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285187
|
- |
|
cisco
|
identity_services_engine_software
|
Cross-site scripting (XSS) vulnerability in the Mobile Device Management (MDM) portal in Cisco Identity Services Engine (ISE) allows remote attackers to inject arbitrary web script or HTML via an uns…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5504
|
2024-11-21 10:57 |
2013-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285188
|
- |
|
apple
|
iphone_os
|
Passcode Lock in Apple iOS before 7.0.2 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement, and open the Camera app or rea…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5161
|
2024-11-21 10:57 |
2013-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285189
|
- |
|
apple
|
iphone_os
|
Passcode Lock in Apple iOS before 7.0.2 on iPhone devices allows physically proximate attackers to bypass an intended passcode requirement, and dial arbitrary telephone numbers, by making a series of…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5160
|
2024-11-21 10:57 |
2013-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285190
|
- |
|
cisco
|
ios_xr
|
The PPTP-ALG component in CRS Carrier Grade Services Engine (CGSE) and ASR 9000 Integrated Service Module (ISM) in Cisco IOS XR allows remote attackers to cause a denial of service (module reset) via…
|
CWE-20
Improper Input Validation
|
CVE-2013-5498
|
2024-11-21 10:57 |
2013-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|