|
286421
|
- |
|
project-redcap vanderbilt
|
redcap
|
Multiple cross-site scripting (XSS) vulnerabilities in REDCap before 5.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors involving different modules.
|
CWE-79
Cross-site Scripting
|
CVE-2013-4612
|
2024-11-21 10:55 |
2013-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286422
|
- |
|
project-redcap vanderbilt
|
redcap
|
Multiple unspecified vulnerabilities in REDCap before 5.1.1 allow remote attackers to have an unknown impact via vectors involving (1) the Online Designer page or (2) the Manage Survey Participants p…
|
NVD-CWE-noinfo
|
CVE-2013-4611
|
2024-11-21 10:55 |
2013-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286423
|
- |
|
project-redcap vanderbilt
|
redcap
|
Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact and remote attack vectors.
|
NVD-CWE-noinfo
|
CVE-2013-4610
|
2024-11-21 10:55 |
2013-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286424
|
- |
|
project-redcap vanderbilt
|
redcap
|
REDCap before 5.0.4 and 5.1.x before 5.1.3 does not reject certain undocumented syntax within branching logic and calculations, which allows remote authenticated users to bypass intended access restr…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-4609
|
2024-11-21 10:55 |
2013-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286425
|
- |
|
project-redcap vanderbilt
|
redcap
|
Cross-site scripting (XSS) vulnerability in REDCap before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors involving the Graphical Data View & Descriptive Stats page.
|
CWE-79
Cross-site Scripting
|
CVE-2013-4608
|
2024-11-21 10:55 |
2013-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286426
|
9.8 |
CRITICAL
Network
|
swfupload_project
|
swfupload
|
There is an object injection vulnerability in swfupload plugin for wordpress.
|
CWE-74
Injection
|
CVE-2013-4144
|
2024-11-21 10:54 |
2022-07-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286427
|
6.5 |
MEDIUM
Network
|
otrs
|
otrs
|
Kernel/Modules/AgentTicketWatcher.pm in Open Ticket Request System (OTRS) 3.0.x before 3.0.21, 3.1.x before 3.1.17, and 3.2.x before 3.2.8 does not properly restrict tickets, which allows remote atta…
|
CWE-200
Information Exposure
|
CVE-2013-4088
|
2024-11-21 10:54 |
2020-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286428
|
7.5 |
HIGH
Network
|
opensips
|
opensips
|
A Denial of Service (infinite loop) exists in OpenSIPS before 1.10 in lookup.c.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2013-3722
|
2024-11-21 10:54 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286429
|
9.8 |
CRITICAL
Network
|
zabbix
|
zabbix
|
A File Inclusion vulnerability exists in Zabbix 2.0.6 due to inadequate sanitization of request strings in CGI scripts, which could let a remote malicious user execute arbitrary code.
|
CWE-20
Improper Input Validation
|
CVE-2013-3738
|
2024-11-21 10:54 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286430
|
9.8 |
CRITICAL
Network
|
invisioncommunity
|
invision_power_board
|
Invision Power Board (IPB) through 3.x allows admin account takeover leading to code execution.
|
NVD-CWE-noinfo
|
CVE-2013-3725
|
2024-11-21 10:54 |
2020-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|