|
289581
|
- |
|
ibm
|
global_console_manager_16_firmware global_console_manager_32_firmware
|
ping.php in Global Console Manager 16 (GCM16) and Global Console Manager 32 (GCM32) before 1.20.0.22575 on the IBM Avocent 1754 KVM switch allows remote authenticated users to execute arbitrary comma…
|
CWE-20
Improper Input Validation
|
CVE-2013-0526
|
2024-11-21 10:47 |
2013-08-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289582
|
- |
|
ibm
|
websphere_portal
|
Multiple cross-site scripting (XSS) vulnerabilities in IBM WebSphere Portal before 8.0.0.1 CF07 allow remote attackers to inject arbitrary web script or HTML via vectors involving the (1) Portal, (2)…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0587
|
2024-11-21 10:47 |
2013-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289583
|
- |
|
ibm
|
infosphere_information_server
|
Multiple cross-site scripting (XSS) vulnerabilities in IBM InfoSphere Information Server through 8.5 FP3, 8.7 through FP2, and 9.1 allow remote authenticated users to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0585
|
2024-11-21 10:47 |
2013-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289584
|
- |
|
ibm
|
sterling_b2b_integrator
|
IBM Sterling B2B Integrator 5.0 and 5.1 allows remote attackers to cause a denial of service (memory and CPU consumption) via a crafted HTTP (1) Range or (2) Request-Range header.
|
CWE-399
Resource Management Errors
|
CVE-2013-0494
|
2024-11-21 10:47 |
2013-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289585
|
- |
|
ibm
|
informix_open_admin_tool
|
Cross-site scripting (XSS) vulnerability in IBM Informix Open Admin Tool (OAT) 2.x and 3.x before 3.11.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2013-0492
|
2024-11-21 10:47 |
2013-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289586
|
- |
|
ibm
|
api_management
|
Unspecified vulnerability in IBM API Management 2.0 before 2.0.0.1 allows remote attackers to access tenant APIs, and consequently obtain sensitive information or modify data, via unknown vectors.
|
NVD-CWE-noinfo
|
CVE-2013-0559
|
2024-11-21 10:47 |
2013-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289587
|
- |
|
sun
|
sunos
|
Unspecified vulnerability in Oracle Solaris 8, 9, 10, and 11 allows remote attackers to affect confidentiality via unknown vectors related to Utility/Remote Execution Server (in.rexecd).
|
NVD-CWE-noinfo
|
CVE-2013-0398
|
2024-11-21 10:47 |
2013-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289588
|
- |
|
drupal
|
drupal
|
The Image module in Drupal 7.x before 7.19, when a private file system is used, does not properly restrict access to derivative images, which allows remote attackers to read derivative images of othe…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0246
|
2024-11-21 10:47 |
2013-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289589
|
- |
|
drupal
|
drupal
|
The printer friendly version functionality in the Book module in Drupal 6.x before 6.28 and 7.x before 7.19 does not properly restrict access to node that are part of a book outline, which allows rem…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0245
|
2024-11-21 10:47 |
2013-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289590
|
- |
|
moxiecode wordpress fedoraproject
|
plupload wordpress fedora
|
Cross-site scripting (XSS) vulnerability in Plupload.as in Moxiecode plupload before 1.5.5, as used in WordPress before 3.5.1 and other products, allows remote attackers to inject arbitrary web scrip…
|
CWE-79
Cross-site Scripting
|
CVE-2013-0237
|
2024-11-21 10:47 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|