|
287361
|
5.3 |
MEDIUM
Network
|
telaen_project
|
telaen
|
Telean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive information through a specially crafted URL request.
|
CWE-200
Information Exposure
|
CVE-2013-2624
|
2024-11-21 10:52 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287362
|
6.1 |
MEDIUM
Network
|
telaen_project
|
telaen
|
Cross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the "f_email" parameter in index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2623
|
2024-11-21 10:52 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287363
|
6.1 |
MEDIUM
Network
|
uebimiau
|
uebimiau
|
Cross-site Scripting (XSS) in UebiMiau 2.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the "selected_theme" parameter in error.php.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2622
|
2024-11-21 10:52 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287364
|
6.1 |
MEDIUM
Network
|
telaen_project
|
telaen
|
Open Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary websites via a crafted URL.
|
CWE-601
Open Redirect
|
CVE-2013-2621
|
2024-11-21 10:52 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287365
|
8.8 |
HIGH
Network
|
asus
|
rt-n56u_firmware rt-n10u_firmware dsl-n55u_firmware rt-ac66u_firmware rt-n15u_firmware rt-n53_firmware rt-n16_firmware
|
ASUS RT-N56U devices allow CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2013-3093
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287366
|
7.5 |
HIGH
Network
|
netgear
|
wndr4700_firmware
|
NetGear WNDR4700 Media Server devices with firmware 1.0.0.34 allow remote attackers to cause a denial of service (device crash).
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2013-3074
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287367
|
9.8 |
CRITICAL
Network
|
netgear
|
wndr4700_firmware
|
NETGEAR Centria WNDR4700 devices with firmware 1.0.0.34 allow authentication bypass.
|
CWE-287
Improper Authentication
|
CVE-2013-3071
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287368
|
6.1 |
MEDIUM
Network
|
united-security-providers
|
secure_entry_server
|
Secure Entry Server before 4.7.0 contains a URI Redirection vulnerability which could allow remote attackers to conduct phishing attacks due to HSP_AbsoluteRedirects being disabled by default.
|
CWE-601
Open Redirect
|
CVE-2013-2764
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287369
|
9.8 |
CRITICAL
Network
|
belkin
|
wemo_switch_firmware
|
Belkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2013-2748
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287370
|
6.1 |
MEDIUM
Network
|
podpress_project
|
podpress
|
Cross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via the 'playerID' parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2714
|
2024-11-21 10:52 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|