|
285041
|
- |
|
sap
|
netweaver
|
The Live Update webdynpro application (webdynpro/dispatcher/sap.com/tc~slm~ui_lup/LUP) in SAP NetWeaver 7.31 and earlier allows remote attackers to read arbitrary files and directories via an XML doc…
|
NVD-CWE-noinfo
|
CVE-2013-6244
|
2024-11-21 10:58 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285042
|
- |
|
landing_pages_project
|
landing_pages_plugin
|
SQL injection vulnerability in the Landing Pages plugin 1.2.3, before 20131009, and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the "post" parameter to index.p…
|
CWE-89
SQL Injection
|
CVE-2013-6243
|
2024-11-21 10:58 |
2013-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285043
|
- |
|
vmware
|
vcenter_server
|
Session fixation vulnerability in the vSphere Web Client Server in VMware vCenter Server 5.0 before Update 3 allows remote attackers to hijack web sessions and gain privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5971
|
2024-11-21 10:58 |
2013-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285044
|
- |
|
vmware
|
esx esxi
|
hostd-vmdb in VMware ESXi 4.0 through 5.0 and ESX 4.0 through 4.1 allows remote attackers to cause a denial of service (hostd-vmdb service outage) by modifying management traffic.
|
CWE-20
Improper Input Validation
|
CVE-2013-5970
|
2024-11-21 10:58 |
2013-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285045
|
- |
|
vbulletin
|
vbulletin
|
The install/upgrade.php scripts in vBulletin 4.1 and 5 allow remote attackers to create administrative accounts via the customerid, htmldata[password], htmldata[confirmpassword], and htmldata[email] …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6129
|
2024-11-21 10:58 |
2013-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285046
|
- |
|
dlink
|
dir-100
|
Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrators to execute arbitrary commands via a long set/r…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-6027
|
2024-11-21 10:58 |
2013-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285047
|
- |
|
dlink alphanetworks planex
|
di-604s tm-g5240 di-524up di-604up di-624s di-604\+ dir-120 dir-100 vdsl_asl-55052 vdsl_asl-56552 brl-04r brl-04cw brl-04ur
|
The web interface on D-Link DIR-100, DIR-120, DI-624S, DI-524UP, DI-604S, DI-604UP, DI-604+, and TM-G5240 routers; Planex BRL-04R, BRL-04UR, and BRL-04CW routers; and Alpha Networks routers allows re…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6026
|
2024-11-21 10:58 |
2013-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285048
|
- |
|
sybase
|
adaptive_server_enterprise
|
The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to read arbitrary files via a SQL statement containing an XML document with an exter…
|
CWE-94
Code Injection
|
CVE-2013-6025
|
2024-11-21 10:58 |
2013-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285049
|
- |
|
watchguard
|
fireware
|
Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in a cookie.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-6021
|
2024-11-21 10:58 |
2013-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285050
|
- |
|
juniper
|
junos
|
Juniper Junos 10.0 before 10.0S28, 10.4 before 10.4R7, 11.1 before 11.1R5, 11.2 before 11.2R2, and 11.4 before 11.4R1, when in a Next-Generation Multicast VPN (NGEN MVPN) environment, allows remote a…
|
CWE-20
Improper Input Validation
|
CVE-2013-6170
|
2024-11-21 10:58 |
2013-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|