|
284771
|
- |
|
mcafee
|
email_gateway
|
McAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2013-6349
|
2024-11-21 10:59 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284772
|
- |
|
apache
|
struts
|
Multiple cross-site scripting (XSS) vulnerabilities in Apache Struts 2.3.15.3 allow remote attackers to inject arbitrary web script or HTML via the namespace parameter to (1) actionNames.action and (…
|
CWE-79
Cross-site Scripting
|
CVE-2013-6348
|
2024-11-21 10:59 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284773
|
- |
|
novell
|
zenworks_configuration_management
|
Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2013-6347
|
2024-11-21 10:59 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284774
|
- |
|
novell
|
zenworks_configuration_management
|
Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack the authentication of unspecified vic…
|
CWE-352
Origin Validation Error
|
CVE-2013-6346
|
2024-11-21 10:59 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284775
|
- |
|
novell
|
zenworks_configuration_management
|
Unspecified vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 has unknown impact and attack vectors related to an "Application Exception."
|
NVD-CWE-noinfo
|
CVE-2013-6345
|
2024-11-21 10:59 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284776
|
- |
|
novell
|
zenworks_configuration_management
|
The ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows attackers to conduct cross-frame scripting attacks via unknown vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-6344
|
2024-11-21 10:59 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284777
|
9.8 |
CRITICAL
Network
|
qnap
|
viocard-30_firmware viocard-100_firmware viocard-300_firmware viogate-340a_firmware viogate-340_firmware
|
QNAP F_VioCard 2312 and F_VioGate 2308 have hardcoded entries in authorized_keys files. NOTE: 1. All active models are not affected. The last affected model was EOL since 2010. 2. The legacy authoriz…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2013-6276
|
2024-11-21 10:58 |
2021-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284778
|
9.8 |
CRITICAL
Network
|
prestashop
|
prestashop
|
PrestaShop 1.5.5 vulnerable to privilege escalation via a Salesman account via upload module
|
CWE-269
Improper Privilege Management
|
CVE-2013-6295
|
2024-11-21 10:58 |
2020-02-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284779
|
7.5 |
HIGH
Network
|
qnap
|
viocard_300_firmware
|
QNAP VioCard 300 has hardcoded RSA private keys.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2013-6277
|
2024-11-21 10:58 |
2020-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284780
|
6.1 |
MEDIUM
Network
|
tiki
|
tikiwiki_cms\/groupware
|
A Cross-Site Scripting (XSS) vulnerability exists in Tiki Wiki CMG Groupware 11.0 via the id paraZeroClipboard.swf, which could let a remote malicious user execute arbitrary code.
|
CWE-79
Cross-site Scripting
|
CVE-2013-6022
|
2024-11-21 10:58 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|