|
286921
|
6.5 |
MEDIUM
Network
|
netgear
|
wnr3500u_firmware wnr3500l_firmware
|
NETGEAR WNR3500U and WNR3500L routers uses form tokens abased solely on router's current date and time, which allows attackers to guess the CSRF tokens.
|
CWE-352
Origin Validation Error
|
CVE-2013-3516
|
2024-11-21 10:53 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286922
|
5.4 |
MEDIUM
Network
|
netgear
|
wnr3500u_firmware wnr3500l_firmware
|
Cross-site scripting (XSS) vulnerability in NETGEAR WNR3500U and WNR3500L.
|
CWE-79
Cross-site Scripting
|
CVE-2013-3517
|
2024-11-21 10:53 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286923
|
7.8 |
HIGH
Local
|
nitropdf
|
nitro_reader nitro_pro
|
Nitro Pro 7.5.0.22 and earlier and Nitro Reader 2.5.0.36 and earlier allow remote attackers to execute arbitrary code via a crafted PDF file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-3553
|
2024-11-21 10:53 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286924
|
7.8 |
HIGH
Local
|
nitropdf
|
nitro_reader nitro_pro
|
Nitro Pro 7.5.0.29 and earlier and Nitro Reader 2.5.0.45 and earlier allow remote attackers to execute arbitrary code via a crafted PDF file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-3552
|
2024-11-21 10:53 |
2018-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286925
|
- |
|
exponentcms
|
exponent_cms
|
Directory traversal vulnerability in install/popup.php in Exponent CMS before 2.2.0 RC1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the page parameter.
|
CWE-22
Path Traversal
|
CVE-2013-3295
|
2024-11-21 10:53 |
2014-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286926
|
- |
|
dell
|
equallogic_ps4000_firmware
|
Directory traversal vulnerability in Dell EqualLogic PS4000 with firmware 6.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI.
|
CWE-22
Path Traversal
|
CVE-2013-3304
|
2024-11-21 10:53 |
2014-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286927
|
- |
|
zemanta
|
related_posts
|
Cross-site request forgery (CSRF) vulnerability in the WordPress Related Posts plugin before 2.6.2 for WordPress allows remote attackers to hijack the authentication of users for requests that change…
|
CWE-352
Origin Validation Error
|
CVE-2013-3476
|
2024-11-21 10:53 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286928
|
- |
|
bufferapp
|
digg_digg
|
Cross-site request forgery (CSRF) vulnerability in he Digg Digg plugin before 5.3.5 for WordPress allows remote attackers to hijack the authentication of users for requests that modify settings via u…
|
CWE-352
Origin Validation Error
|
CVE-2013-3258
|
2024-11-21 10:53 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286929
|
- |
|
zemanta
|
related_posts
|
Cross-site request forgery (CSRF) vulnerability in the Related Posts plugin before 2.7.2 for WordPress allows remote attackers to hijack the authentication of users for requests that modify settings …
|
CWE-352
Origin Validation Error
|
CVE-2013-3257
|
2024-11-21 10:53 |
2014-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286930
|
- |
|
zemanta
|
related_posts
|
Cross-site request forgery (CSRF) vulnerability in the Related Posts by Zemanta plugin before 1.3.2 for WordPress allows remote attackers to hijack the authentication of unspecified users for request…
|
CWE-352
Origin Validation Error
|
CVE-2013-3477
|
2024-11-21 10:53 |
2014-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|