|
284051
|
- |
|
splunk
|
splunk
|
The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string. NOTE: this issue was SPLIT from CVE-2013-6771 per ADT…
|
CWE-94
Code Injection
|
CVE-2013-7394
|
2024-11-21 11:00 |
2014-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284052
|
- |
|
apache
|
subversion
|
The daemonize.py module in Subversion 1.8.0 before 1.8.2 allows local users to gain privileges via a symlink attack on the pid file created for (1) svnwcsub.py or (2) irkerbridge.py when the --pidfil…
|
CWE-59
Link Following
|
CVE-2013-7393
|
2024-11-21 11:00 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284053
|
- |
|
gitlist
|
gitlist
|
Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/.
|
NVD-CWE-Other
|
CVE-2013-7392
|
2024-11-21 11:00 |
2014-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284054
|
- |
|
entity_api_project
|
entity_api
|
The Entity API module 7.x-1.x before 7.x-1.2 for Drupal, when using the (a) Views field or (b) area plugins, allows remote attackers to read restricted entities via the (1) field, (2) header, or (3) …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7391
|
2024-11-21 11:00 |
2014-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284055
|
- |
|
dlink
|
dir-645_firmware dir-645
|
Multiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allow remote attackers to inject arbitrary web script or HTML via the (1) deviceid …
|
CWE-79
Cross-site Scripting
|
CVE-2013-7389
|
2024-11-21 11:00 |
2014-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284056
|
- |
|
google trimble
|
sketchup
|
Heap-based buffer overflow in paintlib, as used in Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689), allows remote attackers to execute arbitrary code via a crafted RLE4-compressed…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-7388
|
2024-11-21 11:00 |
2014-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284057
|
- |
|
vinay_sajip
|
python-gnupg
|
python-gnupg before 0.3.5 allows context-dependent attackers to execute arbitrary commands via shell metacharacters in unspecified vectors.
|
NVD-CWE-Other
|
CVE-2013-7323
|
2024-11-21 11:00 |
2014-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284058
|
- |
|
dleviet
|
datalife_engine
|
Session fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions via the PHPSESSID cookie.
|
NVD-CWE-Other
|
CVE-2013-7387
|
2024-11-21 11:00 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284059
|
- |
|
rom_walton
|
boinc
|
Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in BOINC, possibly 7.2.33, allows remote attackers to cause a denial of service (crash) or possibly ex…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2013-7386
|
2024-11-21 11:00 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284060
|
- |
|
x2go
|
x2go_server
|
x2gocleansessions in X2Go Server before 4.0.0.8 and 4.0.1.x before 4.0.1.10 allows remote authenticated users to gain privileges via unspecified vectors, possibly related to backticks.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7383
|
2024-11-21 11:00 |
2014-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|