|
284271
|
- |
|
typo3
|
typo3
|
The (old) Form Content Element component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated editors to generate arbitrary H…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7081
|
2024-11-21 11:00 |
2013-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284272
|
- |
|
typo3
|
typo3
|
The creating record functionality in Extension table administration library (feuser_adminLib.inc) in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, and 6.0.0 through 6.0.11 allows remote attackers…
|
NVD-CWE-noinfo
|
CVE-2013-7080
|
2024-11-21 11:00 |
2013-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284273
|
- |
|
typo3
|
typo3
|
Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote attackers to redirect users to arb…
|
CWE-20
Improper Input Validation
|
CVE-2013-7079
|
2024-11-21 11:00 |
2013-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284274
|
- |
|
typo3
|
typo3
|
The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote authenticated backend users to unserialize arbit…
|
CWE-310
Cryptographic Issues
|
CVE-2013-7075
|
2024-11-21 11:00 |
2013-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284275
|
- |
|
typo3
|
typo3
|
The Content Editing Wizards component in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 does not check permissions, which allows remote authenticated …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-7073
|
2024-11-21 11:00 |
2013-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284276
|
- |
|
znc
|
znc-msvc
|
Stack-based buffer overflow in fish.cpp in the Fish plugin for ZNC, as used in ZNC for Windows (znc-msvc) 0.206 and earlier, allows remote attackers to cause a denial of service (crash) via a long st…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-7049
|
2024-11-21 11:00 |
2013-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284277
|
- |
|
cisco
|
ios_xe
|
The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authenticat…
|
CWE-287
Improper Authentication
|
CVE-2013-6979
|
2024-11-21 11:00 |
2013-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284278
|
- |
|
cisco
|
unified_communications_manager
|
The disaster recovery system (DRS) component in Cisco Unified Communications Manager (UCM) 9.1(1) and earlier allows remote authenticated users to obtain sensitive device information by reading "extr…
|
CWE-200
Information Exposure
|
CVE-2013-6978
|
2024-11-21 11:00 |
2013-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284279
|
- |
|
efrontlearning
|
efront
|
Multiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated administrators to inject arbitrary web script or HTML via the (1…
|
CWE-79
Cross-site Scripting
|
CVE-2013-7194
|
2024-11-21 11:00 |
2013-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284280
|
- |
|
etoshop
|
c2c_forward_auction_creator
|
Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) pa parameter to auction/asp/list.asp, or the (2) UserID …
|
CWE-89
SQL Injection
|
CVE-2013-7193
|
2024-11-21 11:00 |
2013-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|