|
287931
|
- |
|
mantisbt
|
mantisbt
|
Multiple cross-site scripting (XSS) vulnerabilities in core/summary_api.php in MantisBT 1.2.12 allow remote authenticated users with manager or administrator permissions to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1810
|
2024-11-21 10:50 |
2014-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287932
|
- |
|
cloudbees
|
jenkins
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allow remote attackers to…
|
CWE-352
Origin Validation Error
|
CVE-2013-2034
|
2024-11-21 10:50 |
2014-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287933
|
- |
|
smart-flv_plugin_project
|
smart-flv
|
Multiple cross-site scripting (XSS) vulnerabilities in jwplayer.swf in the smart-flv plugin for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) link or (2) playerr…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1765
|
2024-11-21 10:50 |
2014-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287934
|
- |
|
php-fusion
|
php-fusion
|
Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby parameter to downloads.php; or remote authenticated us…
|
CWE-89
SQL Injection
|
CVE-2013-1803
|
2024-11-21 10:50 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287935
|
- |
|
transifex
|
transifex
|
Transifex command-line client before 0.9 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate.
|
CWE-20
Improper Input Validation
|
CVE-2013-2073
|
2024-11-21 10:50 |
2014-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287936
|
- |
|
php-fusion
|
php-fusion
|
PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1807
|
2024-11-21 10:50 |
2014-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287937
|
- |
|
php-fusion
|
php-fusion
|
Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via a .. (dot dot) in the (1) user_theme parameter to…
|
CWE-22
Path Traversal
|
CVE-2013-1806
|
2024-11-21 10:50 |
2014-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287938
|
- |
|
php-fusion
|
php-fusion
|
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitrary web script or HTML via the (1) highlight parameter to forum/viewthread.php;…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1804
|
2024-11-21 10:50 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287939
|
- |
|
ushahidi
|
ushahidi_platform
|
Cross-site scripting (XSS) vulnerability in Ushahidi Platform 2.5.x through 2.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2025
|
2024-11-21 10:50 |
2014-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287940
|
- |
|
packagekit_project
|
packagekit
|
The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1764
|
2024-11-21 10:50 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|