|
286001
|
7.5 |
HIGH
Network
|
mediawiki fedoraproject
|
mediawiki fedora
|
The CentralNotice extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 sets the Cache-Control header to cache session cookies when a user is autocreated, which allows…
|
CWE-384
Session Fixation
|
CVE-2013-4572
|
2024-11-21 10:55 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286002
|
7.5 |
HIGH
Network
|
gnome redhat
|
evolution evolution_data_server enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
The gpg_ctx_add_recipient function in camel/camel-gpg-context.c in GNOME Evolution 3.8.4 and earlier and Evolution Data Server 3.9.5 and earlier does not properly select the GPG key to use for email …
|
CWE-200
Information Exposure
|
CVE-2013-4166
|
2024-11-21 10:55 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286003
|
6.1 |
MEDIUM
Network
|
hitmyserver
|
hms_testimonials
|
Multiple cross-site scripting (XSS) vulnerabilities in the HMS Testimonials plugin before 2.0.11 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) name, (2) imag…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4241
|
2024-11-21 10:55 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286004
|
6.5 |
MEDIUM
Network
|
flippy_project
|
flippy
|
The Flippy module 7.x-1.x before 7.x-1.2 for Drupal does not properly restrict access to nodes, which allows remote authenticated users with the permission to access content to read a link or alias t…
|
CWE-200
Information Exposure
|
CVE-2013-4187
|
2024-11-21 10:55 |
2020-01-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286005
|
8.8 |
HIGH
Network
|
gitlab
|
gitlab gitlab-shell
|
The parse_cmd function in lib/gitlab_shell.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, and Enterprise Edition before 6.2.1 and gitlab-shell before 1.7.8 allows remote authenticated…
|
CWE-269
Improper Privilege Management
|
CVE-2013-4583
|
2024-11-21 10:55 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286006
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab gitlab-shell
|
The (1) create_branch, (2) create_tag, (3) import_project, and (4) fork_project functions in lib/gitlab_projects.rb in GitLab 5.0 before 5.4.2, Community Edition before 6.2.4, Enterprise Edition befo…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2013-4582
|
2024-11-21 10:55 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286007
|
9.8 |
CRITICAL
Network
|
pwgen_project
|
pwgen
|
The Phonemes mode in Pwgen 2.06 generates predictable passwords, which makes it easier for context-dependent attackers to guess the password via a brute-force attack.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2013-4441
|
2024-11-21 10:55 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286008
|
9.1 |
CRITICAL
Network
|
portable_phpmyadmin_project
|
portable_phpmyadmin
|
WordPress Portable phpMyAdmin Plugin has an authentication bypass vulnerability
|
CWE-287
Improper Authentication
|
CVE-2013-4462
|
2024-11-21 10:55 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286009
|
9.1 |
CRITICAL
Network
|
tejimaya
|
openpne
|
OpenPNE 3 versions 3.8.7, 3.6.11, 3.4.21.1, 3.2.7.6, 3.0.8.5 has an External Entity Injection Vulnerability
|
CWE-611
XXE
|
CVE-2013-4333
|
2024-11-21 10:55 |
2020-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286010
|
5.5 |
MEDIUM
Local
|
mysecureshell_project
|
mysecureshell
|
mysecureshell 1.31: Local Information Disclosure Vulnerability
|
CWE-200
Information Exposure
|
CVE-2013-4176
|
2024-11-21 10:55 |
2020-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|