|
288991
|
7.5 |
HIGH
Network
|
netapp
|
oncommand_system_manager
|
NetApp OnCommand System Manager 2.1 and earlier allows remote attackers to include arbitrary files through specially crafted requests to the "diagnostic" page using the SnapMirror log path parameter.
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2013-3321
|
2024-11-21 10:53 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288992
|
6.1 |
MEDIUM
Network
|
netapp
|
oncommand_system_manager
|
Cross-site Scripting (XSS) vulnerability in NetApp OnCommand System Manager before 2.2 allows remote attackers to inject arbitrary web script or HTML via the 'full-name' and 'comment' fields.
|
CWE-79
Cross-site Scripting
|
CVE-2013-3320
|
2024-11-21 10:53 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288993
|
9.8 |
CRITICAL
Network
|
netgear
|
wnr1000_firmware
|
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass via the NtgrBak key.
|
CWE-287
Improper Authentication
|
CVE-2013-3317
|
2024-11-21 10:53 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288994
|
9.8 |
CRITICAL
Network
|
netgear
|
wnr1000_firmware
|
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".
|
CWE-287
Improper Authentication
|
CVE-2013-3316
|
2024-11-21 10:53 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288995
|
9.8 |
CRITICAL
Network
|
vtiger
|
vtiger_crm
|
vtiger CRM 5.4.0 and earlier contain an Authentication Bypass Vulnerability due to improper authentication validation in the validateSession function.
|
CWE-287
Improper Authentication
|
CVE-2013-3215
|
2024-11-21 10:53 |
2020-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288996
|
9.8 |
CRITICAL
Network
|
vtiger
|
vtiger_crm
|
vtiger CRM 5.4.0 and earlier contain a PHP Code Injection Vulnerability in 'vtigerolservice.php'.
|
CWE-74
Injection
|
CVE-2013-3214
|
2024-11-21 10:53 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288997
|
8.1 |
HIGH
Network
|
vtiger
|
vtiger_crm
|
vtiger CRM 5.4.0 and earlier contain local file-include vulnerabilities in 'customerportal.php' which allows remote attackers to view files and execute local script code.
|
CWE-74
Injection
|
CVE-2013-3212
|
2024-11-21 10:53 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288998
|
9.8 |
CRITICAL
Network
|
xnview
|
xnview
|
XnView 2.03 has an integer overflow vulnerability
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2013-3493
|
2024-11-21 10:53 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288999
|
9.8 |
CRITICAL
Network
|
xnview
|
xnview
|
XnView 2.03 has a stack-based buffer overflow vulnerability
|
CWE-787
Out-of-bounds Write
|
CVE-2013-3492
|
2024-11-21 10:53 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289000
|
9.6 |
CRITICAL
Network
|
irfanview
|
flashpix_plugin
|
IrfanView FlashPix Plugin 4.3.4 0 has an Integer Overflow Vulnerability
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2013-3486
|
2024-11-21 10:53 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|