|
286831
|
- |
|
ds3
|
authentication_server
|
ServerAdmin/ErrorViewer.jsp in DS3 Authentication Server allow remote attackers to inject arbitrary error-page text via the message parameter.
|
CWE-20
Improper Input Validation
|
CVE-2013-4098
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286832
|
- |
|
ds3
|
authentication_server
|
ServerAdmin/TestDRConnection.jsp in DS3 Authentication Server allows remote attackers to obtain sensitive information via a direct request, which reveals the installation path in a -REG-E-OPEN error …
|
CWE-22
Path Traversal
|
CVE-2013-4097
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286833
|
- |
|
ds3
|
authentication_server
|
ServerAdmin/TestTelnetConnection.jsp in DS3 Authentication Server allows remote authenticated users to execute arbitrary commands via shell metacharacters in the HOST_NAME field.
|
CWE-20
Improper Input Validation
|
CVE-2013-4096
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286834
|
- |
|
imperva
|
securesphere
|
plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to execute arbitrary commands via a task with a …
|
CWE-20
Improper Input Validation
|
CVE-2013-4095
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286835
|
- |
|
imperva
|
securesphere
|
The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) priv…
|
CWE-20
Improper Input Validation
|
CVE-2013-4094
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286836
|
- |
|
imperva
|
securesphere
|
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive information via (1) a direct request to dwr/call/plaincall/Asyn…
|
CWE-22
Path Traversal
|
CVE-2013-4093
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286837
|
- |
|
imperva
|
securesphere
|
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain sensitive information by leveraging the presence of (1) a sess…
|
CWE-255
Credentials Management
|
CVE-2013-4092
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286838
|
- |
|
imperva
|
securesphere
|
The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 does not have an off autocomplete attribute for the password (aka j_password) field on the secsphLogin.jsp …
|
CWE-255
Credentials Management
|
CVE-2013-4091
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286839
|
- |
|
kent-web
|
clip-mail
|
Cross-site scripting (XSS) vulnerability in KENT-WEB CLIP-MAIL before 3.4, when Internet Explorer 7 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an unspecifi…
|
CWE-79
Cross-site Scripting
|
CVE-2013-3649
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286840
|
- |
|
kent-web
|
post-mail
|
Cross-site scripting (XSS) vulnerability in KENT-WEB POST-MAIL before 6.7, when Internet Explorer 7 or earlier is used, allows remote attackers to inject arbitrary web script or HTML via an unspecifi…
|
CWE-79
Cross-site Scripting
|
CVE-2013-3648
|
2024-11-21 10:54 |
2013-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|