|
284061
|
7.8 |
HIGH
Local
|
splunk
|
splunk
|
Splunk 5.0.3 has an Unquoted Service Path in Windows for Universal Forwarder which can allow an attacker to escalate privileges
|
CWE-269
Improper Privilege Management
|
CVE-2013-6773
|
2024-11-21 10:59 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284062
|
4.3 |
MEDIUM
Network
|
splunk
|
splunk
|
Splunk before 5.0.4 lacks X-Frame-Options which can allow Clickjacking
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2013-6772
|
2024-11-21 10:59 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284063
|
8.8 |
HIGH
Network
|
prestashop
|
prestashop
|
PrestaShop 1.5.5 allows remote authenticated attackers to execute arbitrary code by uploading a crafted profile and then accessing it in the module/ directory.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2013-6358
|
2024-11-21 10:59 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284064
|
5.4 |
MEDIUM
Network
|
pivotal_software
|
spring_framework
|
The JavaScriptUtils.javaScriptEscape method in web/util/JavaScriptUtils.java in Spring MVC in Spring Framework before 3.2.2 does not properly escape certain characters, which allows remote attackers …
|
CWE-79
Cross-site Scripting
|
CVE-2013-6430
|
2024-11-21 10:59 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284065
|
6.1 |
MEDIUM
Network
|
redhat
|
jboss_enterprise_application_platform jboss_portal
|
JBossWeb Bayeux has reflected XSS
|
CWE-79
Cross-site Scripting
|
CVE-2013-6495
|
2024-11-21 10:59 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284066
|
5.3 |
MEDIUM
Network
|
miwisoft
|
mijosearch
|
The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the installation pa…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2013-6879
|
2024-11-21 10:59 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284067
|
6.1 |
MEDIUM
Network
|
miwisoft
|
mijosearch
|
Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla! allows remote attackers to inject arbitrary web script or HTML via the query parameter to c…
|
CWE-79
Cross-site Scripting
|
CVE-2013-6878
|
2024-11-21 10:59 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284068
|
6.1 |
MEDIUM
Network
|
elvedia
|
flashcanvas
|
Open redirect in proxy.php in FlashCanvas before 1.6 allows remote attackers to redirect users to arbitrary web sites and conduct cross-site scripting (XSS) attacks via the HTTP Referer header.
|
CWE-79
Cross-site Scripting
|
CVE-2013-6880
|
2024-11-21 10:59 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284069
|
8.8 |
HIGH
Network
|
d-link
|
dsl6740u_firmware
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the D-Link DSL-6740U gateway (Rev. H1) allow remote attackers to hijack the authentication of administrators for requests that change adm…
|
CWE-352
Origin Validation Error
|
CVE-2013-6811
|
2024-11-21 10:59 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284070
|
6.5 |
MEDIUM
Network
|
nokogiri debian redhat
|
nokogiri debian_linux openstack cloudforms_management_engine satellite subscription_asset_manager enterprise_mrg
|
Nokogiri gem 1.5.x and 1.6.x has DoS while parsing XML entities by failing to apply limits
|
CWE-776
XML Entity Expansion
|
CVE-2013-6461
|
2024-11-21 10:59 |
2019-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|