|
288521
|
- |
|
chatelao
|
php_address_book
|
Multiple SQL injection vulnerabilities in PHP Address Book 8.2.5 allow remote attackers to execute arbitrary SQL commands via unspecified parameters to (1) edit.php or (2) import.php. NOTE: the view…
|
CWE-89
SQL Injection
|
CVE-2013-1748
|
2024-11-21 10:50 |
2013-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288522
|
6.1 |
MEDIUM
Network
|
phpmyadmin
|
phpmyadmin
|
Multiple cross-site scripting (XSS) vulnerabilities in tbl_gis_visualization.php in phpMyAdmin 3.5.x before 3.5.8 might allow remote attackers to inject arbitrary web script or HTML via the (1) visua…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1937
|
2024-11-21 10:50 |
2013-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288523
|
- |
|
xen
|
xen
|
Xen 4.2.x, 4.1.x, and earlier, when the hypervisor is running "under memory pressure" and the Xen Security Module (XSM) is enabled, uses the wrong ordering of operations when extending the per-domain…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1920
|
2024-11-21 10:50 |
2013-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288524
|
- |
|
haproxy
|
haproxy
|
Buffer overflow in HAProxy 1.4 through 1.4.22 and 1.5-dev through 1.5-dev17, when HTTP keep-alive is enabled, using HTTP keywords in TCP inspection rules, and running with rewrite rules that appends …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-1912
|
2024-11-21 10:50 |
2013-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288525
|
- |
|
redhat
|
packstack openstack_folsom openstack_essex
|
PackStack 2012.2.3 in Red Hat OpenStack Essex and Folsom can create the answer file in insecure directories such as /tmp or the current working directory, which allows local users to modify deployed …
|
CWE-255
Credentials Management
|
CVE-2013-1815
|
2024-11-21 10:50 |
2013-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288526
|
- |
|
ruby-lang
|
ruby
|
lib/rexml/text.rb in the REXML parser in Ruby before 1.9.3-p392 allows remote attackers to cause a denial of service (memory consumption and crash) via crafted text nodes in an XML document, aka an X…
|
CWE-20
Improper Input Validation
|
CVE-2013-1821
|
2024-11-21 10:50 |
2013-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288527
|
- |
|
digineo
|
thumbshooter
|
lib/thumbshooter.rb in the Thumbshooter 0.1.5 gem for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
|
CWE-94
Code Injection
|
CVE-2013-1898
|
2024-11-21 10:50 |
2013-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288528
|
- |
|
dan_kubb
|
extlib
|
The extlib gem 0.9.15 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cau…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1802
|
2024-11-21 10:50 |
2013-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288529
|
- |
|
john_nunemaker
|
httparty
|
The httparty gem 0.9.0 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or ca…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1801
|
2024-11-21 10:50 |
2013-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288530
|
- |
|
john_nunemaker
|
crack
|
The crack gem 0.3.1 and earlier for Ruby does not properly restrict casts of string values, which might allow remote attackers to conduct object-injection attacks and execute arbitrary code, or cause…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1800
|
2024-11-21 10:50 |
2013-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|