|
288251
|
- |
|
php-fusion
|
php-fusion
|
Multiple SQL injection vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to execute arbitrary SQL commands via the (1) orderby parameter to downloads.php; or remote authenticated us…
|
CWE-89
SQL Injection
|
CVE-2013-1803
|
2024-11-21 10:50 |
2014-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288252
|
- |
|
transifex
|
transifex
|
Transifex command-line client before 0.9 does not validate X.509 certificates, which allows man-in-the-middle attackers to spoof a Transifex server via an arbitrary certificate.
|
CWE-20
Improper Input Validation
|
CVE-2013-2073
|
2024-11-21 10:50 |
2014-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288253
|
- |
|
php-fusion
|
php-fusion
|
PHP-Fusion before 7.02.06 stores backup files with predictable filenames in an unrestricted directory under the web document root, which might allow remote attackers to obtain sensitive information v…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1807
|
2024-11-21 10:50 |
2014-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288254
|
- |
|
php-fusion
|
php-fusion
|
Multiple directory traversal vulnerabilities in PHP-Fusion before 7.02.06 allow remote authenticated users to include and execute arbitrary files via a .. (dot dot) in the (1) user_theme parameter to…
|
CWE-22
Path Traversal
|
CVE-2013-1806
|
2024-11-21 10:50 |
2014-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288255
|
- |
|
php-fusion
|
php-fusion
|
Multiple cross-site scripting (XSS) vulnerabilities in PHP-Fusion before 7.02.06 allow remote attackers to inject arbitrary web script or HTML via the (1) highlight parameter to forum/viewthread.php;…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1804
|
2024-11-21 10:50 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288256
|
- |
|
ushahidi
|
ushahidi_platform
|
Cross-site scripting (XSS) vulnerability in Ushahidi Platform 2.5.x through 2.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2025
|
2024-11-21 10:50 |
2014-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288257
|
- |
|
packagekit_project
|
packagekit
|
The Zypper (aka zypp) backend in PackageKit before 0.8.8 allows local users to downgrade packages via the "install updates" method.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1764
|
2024-11-21 10:50 |
2014-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288258
|
- |
|
jenkins cloudbees
|
jenkins
|
Cross-site scripting (XSS) vulnerability in Jenkins before 1.514, LTS before 1.509.1, and Enterprise 1.466.x before 1.466.14.1 and 1.480.x before 1.480.4.1 allows remote authenticated users with writ…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2033
|
2024-11-21 10:50 |
2014-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288259
|
- |
|
restful_web_services_project
|
restful_web_services
|
The RESTful Web Services (RESTWS) module 7.x-1.x before 7.x-1.3 and 7.x-2.x before 7.x-2.0-alpha5 for Drupal, when page caching is enabled and anonymous users are assigned RESTWS permissions, allows …
|
CWE-20
Improper Input Validation
|
CVE-2013-1946
|
2024-11-21 10:50 |
2014-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288260
|
- |
|
ganglia
|
ganglia-web
|
Cross-site scripting (XSS) vulnerability in views_view.php in Ganglia Web 3.5.7 allows remote attackers to inject arbitrary web script or HTML via the view_name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2013-1770
|
2024-11-21 10:50 |
2014-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|