|
287001
|
- |
|
phpmyadmin
|
phpmyadmin
|
export.php (aka the export script) in phpMyAdmin 4.x before 4.0.0-rc3 overwrites global variables on the basis of the contents of the POST superglobal array, which allows remote authenticated users t…
|
NVD-CWE-noinfo
|
CVE-2013-3241
|
2024-11-21 10:53 |
2013-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287002
|
- |
|
phpmyadmin
|
phpmyadmin
|
Directory traversal vulnerability in the Export feature in phpMyAdmin 4.x before 4.0.0-rc3 allows remote authenticated users to read arbitrary files or possibly have unspecified other impact via a pa…
|
CWE-22
Path Traversal
|
CVE-2013-3240
|
2024-11-21 10:53 |
2013-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287003
|
- |
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3, when a SaveDir directory is configured, allows remote authenticated users to execute arbitrary code by using a double extension in the filename…
|
CWE-94
Code Injection
|
CVE-2013-3239
|
2024-11-21 10:53 |
2013-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287004
|
- |
|
phpmyadmin
|
phpmyadmin
|
phpMyAdmin 3.5.x before 3.5.8 and 4.x before 4.0.0-rc3 allows remote authenticated users to execute arbitrary code via a /e\x00 sequence, which is not properly handled before making a preg_replace fu…
|
NVD-CWE-noinfo
|
CVE-2013-3238
|
2024-11-21 10:53 |
2013-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287005
|
- |
|
cybozu
|
cybozu_office
|
Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0 allows remote attackers to hijack the authentication of arbitrary users for requests that change mob…
|
CWE-352
Origin Validation Error
|
CVE-2013-3269
|
2024-11-21 10:53 |
2013-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287006
|
- |
|
novell
|
imanager
|
Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.
|
CWE-287
Improper Authentication
|
CVE-2013-3268
|
2024-11-21 10:53 |
2013-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287007
|
- |
|
linux
|
linux_kernel
|
The vsock_stream_sendmsg function in net/vmw_vsock/af_vsock.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive informatio…
|
CWE-200
Information Exposure
|
CVE-2013-3237
|
2024-11-21 10:53 |
2013-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287008
|
- |
|
linux
|
linux_kernel
|
The vmci_transport_dgram_dequeue function in net/vmw_vsock/vmci_transport.c in the Linux kernel before 3.9-rc7 does not properly initialize a certain length variable, which allows local users to obta…
|
CWE-200
Information Exposure
|
CVE-2013-3236
|
2024-11-21 10:53 |
2013-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287009
|
- |
|
linux
|
linux_kernel
|
net/tipc/socket.c in the Linux kernel before 3.9-rc7 does not initialize a certain data structure and a certain length variable, which allows local users to obtain sensitive information from kernel s…
|
CWE-200
Information Exposure
|
CVE-2013-3235
|
2024-11-21 10:53 |
2013-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287010
|
- |
|
linux
|
linux_kernel
|
The rose_recvmsg function in net/rose/af_rose.c in the Linux kernel before 3.9-rc7 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel s…
|
CWE-200
Information Exposure
|
CVE-2013-3234
|
2024-11-21 10:53 |
2013-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|