|
285411
|
8.8 |
HIGH
Network
|
dlink
|
dir-100_firmware
|
D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters
|
CWE-287
Improper Authentication
|
CVE-2013-7051
|
2024-11-21 11:00 |
2020-02-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285412
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_desktop_central
|
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file w…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2013-7390
|
2024-11-21 11:00 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285413
|
7.8 |
HIGH
Local
|
daum
|
potplayer
|
PotPlayer 1.5.40688: .avi File Memory Corruption
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-7185
|
2024-11-21 11:00 |
2020-01-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285414
|
9.8 |
CRITICAL
Network
|
ep_imageconvert_project
|
ep_imageconvert
|
The Etherpad Lite ep_imageconvert Plugin has a Remote Command Injection Vulnerability
|
CWE-74
Injection
|
CVE-2013-7380
|
2024-11-21 11:00 |
2020-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285415
|
6.1 |
MEDIUM
Network
|
shaarli_project
|
shaarli
|
Multiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML via the URL to the (1) showRSS, (2) showATOM, or (3) showDail…
|
CWE-79
Cross-site Scripting
|
CVE-2013-7351
|
2024-11-21 11:00 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285416
|
6.1 |
MEDIUM
Network
|
plone
|
plone
|
Multiple cross-site scripting (XSS) vulnerabilities in Zope, as used in Plone 3.3.x through 3.3.6, 4.0.x through 4.0.9, 4.1.x through 4.1.6, 4.2.x through 4.2.7, and 4.3 through 4.3.2, allow remote a…
|
CWE-79
Cross-site Scripting
|
CVE-2013-7062
|
2024-11-21 11:00 |
2020-01-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285417
|
6.1 |
MEDIUM
Network
|
fibranet
|
monitorix
|
Cross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
|
CWE-79
Cross-site Scripting
|
CVE-2013-7071
|
2024-11-21 11:00 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285418
|
9.8 |
CRITICAL
Network
|
fibranet
|
monitorix
|
The handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the URI.
|
CWE-74
Injection
|
CVE-2013-7070
|
2024-11-21 11:00 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285419
|
6.1 |
MEDIUM
Network
|
sencha debian
|
connect debian_linux
|
node-connects before 2.8.2 has cross site scripting in Sencha Labs Connect middleware (vulnerability due to incomplete fix for CVE-2013-7370)
|
CWE-79
Cross-site Scripting
|
CVE-2013-7371
|
2024-11-21 11:00 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285420
|
6.1 |
MEDIUM
Network
|
redhat sencha opensuse debian
|
openshift connect opensuse debian_linux
|
node-connect before 2.8.1 has XSS in the Sencha Labs Connect middleware
|
CWE-79
Cross-site Scripting
|
CVE-2013-7370
|
2024-11-21 11:00 |
2019-12-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|