|
287441
|
- |
|
rubygems
|
mini_magick
|
lib/mini_magick.rb in the MiniMagick Gem 1.3.1 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
|
CWE-94
Code Injection
|
CVE-2013-2616
|
2024-11-21 10:52 |
2013-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287442
|
- |
|
rubygems
|
fastreader
|
lib/entry_controller.rb in the fastreader Gem 1.0.8 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in a URL.
|
CWE-94
Code Injection
|
CVE-2013-2615
|
2024-11-21 10:52 |
2013-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287443
|
9.8 |
CRITICAL
Network
|
milboj
|
flash_tool
|
The flash_tool gem through 0.6.0 for Ruby allows command execution via shell metacharacters in the name of a downloaded file.
|
CWE-77
Command Injection
|
CVE-2013-2513
|
2024-11-21 10:51 |
2023-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287444
|
9.8 |
CRITICAL
Network
|
ftpd_project
|
ftpd
|
The ftpd gem 0.2.1 for Ruby allows remote attackers to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command argument within FTP protocol traffic.
|
CWE-78
OS Command
|
CVE-2013-2512
|
2024-11-21 10:51 |
2021-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287445
|
7.8 |
HIGH
Local
|
zpanel_project
|
zpanel
|
ZPanel through 10.1.0 has Remote Command Execution
|
NVD-CWE-noinfo
|
CVE-2013-2097
|
2024-11-21 10:51 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287446
|
5.5 |
MEDIUM
Local
|
kde
|
paste_applet
|
The KRandom::random function in KDE Paste Applet after 4.10.5 in kdeplasma-addons uses the GNU C Library rand function's linear congruential generator, which makes it easier for context-dependent att…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2013-2213
|
2024-11-21 10:51 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287447
|
8.4 |
HIGH
Local
|
kde
|
paste_applet
|
The %{password(...)} macro in pastemacroexpander.cpp in the KDE Paste Applet before 4.10.5 in kdeplasma-addons does not properly generate passwords, which allows context-dependent attackers to bypass…
|
CWE-287
Improper Authentication
|
CVE-2013-2120
|
2024-11-21 10:51 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287448
|
8.8 |
HIGH
Network
|
undolog
|
wp_cleanfix
|
WordPress plugin wp-cleanfix has Remote Code Execution
|
CWE-352
Origin Validation Error
|
CVE-2013-2109
|
2024-11-21 10:51 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287449
|
5.4 |
MEDIUM
Network
|
undolog
|
cleanfix
|
WordPress WP Cleanfix Plugin 2.4.4 has CSRF
|
CWE-352
Origin Validation Error
|
CVE-2013-2108
|
2024-11-21 10:51 |
2020-02-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287450
|
6.1 |
MEDIUM
Network
|
viewgit_project
|
viewgit
|
Multiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script or HTML via a (1) tag name to the Shortlog table in templates/…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2294
|
2024-11-21 10:51 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|