|
287741
|
- |
|
lockon
|
ec-cube
|
Cross-site scripting (XSS) vulnerability in the shopping-cart screen in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2312
|
2024-11-21 10:51 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287742
|
- |
|
moodle
|
moodle
|
The MoodleQuickForm class in lib/formslib.php in Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not properly handle a certain array-element syntax, which …
|
CWE-20
Improper Input Validation
|
CVE-2013-2083
|
2024-11-21 10:51 |
2013-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287743
|
- |
|
moodle
|
moodle
|
Moodle through 2.1.10, 2.2.x before 2.2.10, 2.3.x before 2.3.7, and 2.4.x before 2.4.4 does not enforce capability requirements for reading blog comments, which allows remote attackers to obtain sens…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2082
|
2024-11-21 10:51 |
2013-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287744
|
- |
|
web2py
|
web2py
|
Cross-site scripting (XSS) vulnerability in static/js/share.js (aka the social bookmarking widget) in Web2py before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecifie…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2311
|
2024-11-21 10:51 |
2013-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287745
|
- |
|
softbanktech
|
online_service_gate
|
The (1) OWA Helper and (2) OSG Lite programs in SoftBank Online Service Gate allow remote authenticated users to discover their own passwords, and consequently bypass an Office 365 restriction, via u…
|
CWE-200
Information Exposure
|
CVE-2013-2308
|
2024-11-21 10:51 |
2013-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287746
|
- |
|
hp
|
service_manager_web_tier
|
Cross-site scripting (XSS) vulnerability in HP Service Manager Web Tier 9.31 before 9.31.2004 p2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2321
|
2024-11-21 10:51 |
2013-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287747
|
- |
|
yahoo
|
yahoo\!_browser
|
The Yahoo! Browser application before 1.4.3 for Android allows remote attackers to spoof the address bar via a crafted web site.
|
NVD-CWE-noinfo
|
CVE-2013-2307
|
2024-11-21 10:51 |
2013-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287748
|
- |
|
jb\+
|
jigbrowser\+
|
The jigbrowser+ application before 1.6.4 for Android does not properly open windows, which allows remote attackers to spoof the address bar via a crafted web site.
|
NVD-CWE-noinfo
|
CVE-2013-2306
|
2024-11-21 10:51 |
2013-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287749
|
- |
|
cybozu
|
cybozu_office cybozu_dezie mailwise
|
Cross-site request forgery (CSRF) vulnerability in Cybozu Office before 8.1.6 and 9.x before 9.3.0, Cybozu Dezie before 8.0.7, and Cybozu Mailwise before 5.0.4 allows remote attackers to hijack the a…
|
CWE-352
Origin Validation Error
|
CVE-2013-2305
|
2024-11-21 10:51 |
2013-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287750
|
- |
|
oracle sun
|
jre jdk
|
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and 6 Update 43 and earlier allows remote attackers to affect confidentiality, inte…
|
NVD-CWE-noinfo
|
CVE-2013-2440
|
2024-11-21 10:51 |
2013-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|