|
289181
|
7.8 |
HIGH
Local
|
ibm
|
sterling_external_authentication_server
|
A Command Execution Vulnerability exists in IBM Sterling External Authentication Server 2.2.0, 2.3.01, 2.4.0, and 2.4.1 via an unspecified OS command, which could let a local malicious user execute a…
|
CWE-78
OS Command
|
CVE-2013-0517
|
2024-11-21 10:47 |
2020-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289182
|
4.9 |
MEDIUM
Network
|
simplemachines
|
simple_machines_forum
|
File Disclosure in SMF (SimpleMachines Forum) <= 2.0.3: Forum admin can read files such as the database config.
|
CWE-200
Information Exposure
|
CVE-2013-0192
|
2024-11-21 10:47 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289183
|
8.1 |
HIGH
Network
|
ibm
|
infosphere_information_server
|
IBM InfoSphere Information Server 8.1, 8.5, 8.7, 9.1 has a Session Fixation Vulnerability
|
CWE-384
Session Fixation
|
CVE-2013-0507
|
2024-11-21 10:47 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289184
|
7.5 |
HIGH
Network
|
imagely
|
nextgen_gallery
|
NextGEN Gallery Plugin for WordPress 1.9.10 and 1.9.11 has a Path Disclosure Vulnerability
|
CWE-200
Information Exposure
|
CVE-2013-0291
|
2024-11-21 10:47 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289185
|
5.9 |
MEDIUM
Network
|
pyrad_project fedoraproject
|
pyrad fedora
|
packet.py in pyrad before 2.1 uses weak random numbers to generate RADIUS authenticators and hash passwords, which makes it easier for remote attackers to obtain sensitive information via a brute for…
|
CWE-330
Use of Insufficiently Random Values
|
CVE-2013-0294
|
2024-11-21 10:47 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289186
|
5.4 |
MEDIUM
Network
|
pinboard_project
|
pinboard
|
Pinboard 1.0.6 theme for Wordpress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2013-0286
|
2024-11-21 10:47 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289187
|
7.5 |
HIGH
Network
|
redhat
|
mrg_management_console
|
An import error was introduced in Cumin in the code refactoring in r5310. Server certificate validation is always disabled when connecting to Aviary servers, even if the installed packages on a syste…
|
CWE-295
Improper Certificate Validation
|
CVE-2013-0264
|
2024-11-21 10:47 |
2019-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289188
|
6.5 |
MEDIUM
Network
|
redhat
|
openshift
|
A CSRF issue was found in OpenShift Enterprise 1.2. The web console is using 'Basic authentication' and the REST API has no CSRF attack protection mechanism. This can allow an attacker to obtain the …
|
CWE-352
Origin Validation Error
|
CVE-2013-0196
|
2024-11-21 10:47 |
2019-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289189
|
6.1 |
MEDIUM
Network
|
owncloud
|
owncloud
|
Cross-site scripting (XSS) vulnerability in ownCloud 4.5.5, 4.0.10, and earlier allows remote attackers to inject arbitrary web script or HTML via the action parameter to core/ajax/sharing.php.
|
CWE-79
Cross-site Scripting
|
CVE-2013-0202
|
2024-11-21 10:47 |
2019-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289190
|
7.8 |
HIGH
Local
|
ovirt
|
node
|
oVirt Node: Lock screen accepts F2 to drop to shell causing privilege escalation
|
CWE-269
Improper Privilege Management
|
CVE-2013-0293
|
2024-11-21 10:47 |
2019-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|