|
287051
|
- |
|
emc
|
rsa_authentication_agent
|
EMC RSA Authentication Agent for PAM 7.0 before 7.0.2.1 enforces the maximum number of login attempts within the PAM-enabled application codebase, instead of within the Agent codebase, which makes it…
|
CWE-255
Credentials Management
|
CVE-2013-3271
|
2024-11-21 10:53 |
2013-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287052
|
- |
|
searchblox
|
searchblox
|
Directory traversal vulnerability in servlet/CreateTemplateServlet in SearchBlox before 7.5 build 1 allows remote attackers to overwrite arbitrary files via a .. (dot dot) in the name parameter.
|
CWE-22
Path Traversal
|
CVE-2013-3598
|
2024-11-21 10:53 |
2013-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287053
|
- |
|
searchblox
|
searchblox
|
servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords via a getList action.
|
CWE-200
Information Exposure
|
CVE-2013-3597
|
2024-11-21 10:53 |
2013-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287054
|
- |
|
searchblox
|
searchblox
|
Unrestricted file upload vulnerability in admin/uploadImage.html in SearchBlox before 7.5 build 1 allows remote attackers to execute arbitrary code by uploading an executable file with the image/jpeg…
|
NVD-CWE-Other
|
CVE-2013-3590
|
2024-11-21 10:53 |
2013-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287055
|
- |
|
samsung
|
smart_viewer dvr
|
Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.
|
CWE-287
Improper Authentication
|
CVE-2013-3586
|
2024-11-21 10:53 |
2013-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287056
|
- |
|
samsung
|
smart_viewer
|
Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information via vectors involving (1) direct access to a file …
|
CWE-255
Credentials Management
|
CVE-2013-3585
|
2024-11-21 10:53 |
2013-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287057
|
- |
|
corporater
|
epm_suite
|
Cross-site scripting (XSS) vulnerability in Corporater EPM Suite allows remote attackers to inject arbitrary web script or HTML via the customerId parameter to an unspecified component.
|
CWE-79
Cross-site Scripting
|
CVE-2013-3584
|
2024-11-21 10:53 |
2013-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287058
|
- |
|
corporater
|
epm_suite
|
Cross-site request forgery (CSRF) vulnerability in saveProperties.html in Corporater EPM Suite allows remote attackers to hijack the authentication of arbitrary users for requests that change passwor…
|
CWE-352
Origin Validation Error
|
CVE-2013-3583
|
2024-11-21 10:53 |
2013-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287059
|
- |
|
cisco
|
unified_communications_manager
|
Buffer overflow in Cisco Unified Communications Manager (Unified CM) 7.1(x) before 7.1(5b)su6, 8.5(x) before 8.5(1)su6, 8.6(x) before 8.6(2a)su3, and 9.x before 9.1(2) allows remote authenticated use…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-3462
|
2024-11-21 10:53 |
2013-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287060
|
- |
|
cisco
|
unified_communications_manager
|
Cisco Unified Communications Manager (Unified CM) 8.5(x) and 8.6(x) before 8.6(2a)su3 and 9.x before 9.1(1) does not properly restrict the rate of SIP packets, which allows remote attackers to cause …
|
CWE-399
Resource Management Errors
|
CVE-2013-3461
|
2024-11-21 10:53 |
2013-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|