|
285521
|
- |
|
puppet
|
puppet_enterprise
|
The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended …
|
CWE-255
Credentials Management
|
CVE-2013-4962
|
2024-11-21 10:56 |
2013-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285522
|
- |
|
puppet
|
puppet_enterprise
|
Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows remote attackers to obtain sensitive information.
|
CWE-200
Information Exposure
|
CVE-2013-4961
|
2024-11-21 10:56 |
2013-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285523
|
- |
|
puppet
|
puppet_enterprise
|
Puppet Enterprise before 3.0.1 uses HTTP responses that contain sensitive information without the "no-cache" setting, which might allow local users to obtain sensitive information such as (1) host na…
|
CWE-200
Information Exposure
|
CVE-2013-4959
|
2024-11-21 10:56 |
2013-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285524
|
- |
|
puppet
|
puppet_enterprise
|
Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by leveraging an unattended workstation.
|
CWE-287
Improper Authentication
|
CVE-2013-4958
|
2024-11-21 10:56 |
2013-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285525
|
- |
|
puppetlabs puppet
|
puppet puppet_enterprise
|
Puppet Module Tool (PMT), as used in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, installs modules with weak permissions if thos…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4956
|
2024-11-21 10:56 |
2013-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285526
|
- |
|
puppet
|
puppet_enterprise
|
Open redirect vulnerability in the login page in Puppet Enterprise before 3.0.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the service …
|
CWE-20
Improper Input Validation
|
CVE-2013-4955
|
2024-11-21 10:56 |
2013-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285527
|
- |
|
puppet
|
puppet_enterprise
|
Puppet Enterprise before 3.0.1 does not sufficiently invalidate a session when a user logs out, which might allow remote attackers to hijack sessions by obtaining an old session ID.
|
CWE-20
Improper Input Validation
|
CVE-2013-4762
|
2024-11-21 10:56 |
2013-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285528
|
- |
|
puppetlabs puppet
|
puppet puppet_enterprise
|
Unspecified vulnerability in Puppet 2.7.x before 2.7.23 and 3.2.x before 3.2.4, and Puppet Enterprise 2.8.x before 2.8.3 and 3.0.x before 3.0.1, allows remote attackers to execute arbitrary Ruby prog…
|
NVD-CWE-noinfo
|
CVE-2013-4761
|
2024-11-21 10:56 |
2013-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285529
|
- |
|
opensuse phpmyadmin
|
opensuse phpmyadmin
|
phpMyAdmin 3.5.x and 4.0.x before 4.0.5 allows remote attackers to bypass the clickjacking protection mechanism via certain vectors related to Header.class.php.
|
CWE-20
Improper Input Validation
|
CVE-2013-5029
|
2024-11-21 10:56 |
2013-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285530
|
- |
|
winscp debian opensuse putty simon_tatham
|
winscp debian_linux opensuse putty
|
Integer overflow in PuTTY 0.62 and earlier, WinSCP before 5.1.6, and other products that use PuTTY allows remote SSH servers to cause a denial of service (crash) and possibly execute arbitrary code i…
|
CWE-189
Numeric Errors
|
CVE-2013-4852
|
2024-11-21 10:56 |
2013-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|