|
287641
|
- |
|
quade
|
edit_limit
|
The Edit Limit module 7.x-1.x before 7.x-1.3 for Drupal does not properly restrict access to comments, which allows remote authenticated users with the "edit comments" permission to edit arbitrary co…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2122
|
2024-11-21 10:51 |
2013-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287642
|
- |
|
redhat
|
enterprise_linux
|
A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle failure to obtain wri…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2188
|
2024-11-21 10:51 |
2013-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287643
|
- |
|
hp
|
network_node_manager_i
|
Unspecified vulnerability in HP Network Node Manager i (NNMi) 9.00, 9.1x, and 9.2x allows remote attackers to obtain sensitive information, modify data, or cause a denial of service via unknown vecto…
|
NVD-CWE-noinfo
|
CVE-2013-2351
|
2024-11-21 10:51 |
2013-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287644
|
- |
|
hp
|
san\/iq
|
LeftHand OS (aka SAN iQ) 10.5 and earlier on HP StoreVirtual Storage devices does not provide a mechanism for disabling the HP Support challenge-response root-login feature, which makes it easier for…
|
CWE-255
Credentials Management
|
CVE-2013-2352
|
2024-11-21 10:51 |
2013-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287645
|
8.1 |
HIGH
Network
|
apache
|
struts
|
Apache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled when using the includeParams attribute in the (1) URL or (2) …
|
CWE-94
Code Injection
|
CVE-2013-2115
|
2024-11-21 10:51 |
2013-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287646
|
- |
|
spip
|
spip
|
SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.
|
NVD-CWE-noinfo
|
CVE-2013-2118
|
2024-11-21 10:51 |
2013-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287647
|
- |
|
openstack
|
havana grizzly folsom
|
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by cr…
|
CWE-399
Resource Management Errors
|
CVE-2013-2096
|
2024-11-21 10:51 |
2013-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287648
|
- |
|
wordpress
|
wordpress
|
The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-si…
|
CWE-79 CWE-16
Cross-site Scripting Configuration
|
CVE-2013-2205
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287649
|
- |
|
wordpress tinymce
|
wordpress media
|
moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extracti…
|
CWE-20
Improper Input Validation
|
CVE-2013-2204
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287650
|
- |
|
wordpress
|
wordpress
|
WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an X…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2203
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|