|
283601
|
6.1 |
MEDIUM
Network
|
pixelite
|
events_manager
|
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7477
|
2024-11-21 11:01 |
2019-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283602
|
8.8 |
HIGH
Network
|
simple_fields_project
|
simple_fields
|
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
|
CWE-352
Origin Validation Error
|
CVE-2013-7476
|
2024-11-21 11:01 |
2019-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283603
|
6.1 |
MEDIUM
Network
|
bestwebsoft
|
contact_form
|
The contact-form-plugin plugin before 3.52 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7475
|
2024-11-21 11:01 |
2019-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283604
|
6.1 |
MEDIUM
Network
|
windu
|
windu_cms
|
Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7474
|
2024-11-21 11:01 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283605
|
8.8 |
HIGH
Network
|
windu
|
windu_cms
|
Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.
|
CWE-352
Origin Validation Error
|
CVE-2013-7473
|
2024-11-21 11:01 |
2019-08-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283606
|
6.1 |
MEDIUM
Network
|
count_per_day_project
|
count_per_day
|
The "Count per Day" plugin before 3.2.6 for WordPress allows XSS via the wp-admin/?page=cpd_metaboxes daytoshow parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7472
|
2024-11-21 11:01 |
2019-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283607
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-300_firmware dir-600_firmware dir-645_firmware dir-845_firmware dir-865_firmware
|
An issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before v1.04b11, DIR-300 rev. B, and DIR-865 devices. There is Command Injec…
|
CWE-77
Command Injection
|
CVE-2013-7471
|
2024-11-21 11:01 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283608
|
5.9 |
MEDIUM
Network
|
linux
|
linux_kernel
|
cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstr…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2013-7470
|
2024-11-21 11:01 |
2019-04-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283609
|
8.1 |
HIGH
Network
|
simplemachines
|
simple_machines_forum
|
Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.
|
CWE-94
Code Injection
|
CVE-2013-7468
|
2024-11-21 11:01 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283610
|
6.1 |
MEDIUM
Network
|
simplemachines
|
simple_machines_forum
|
Simple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7467
|
2024-11-21 11:01 |
2019-03-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|