|
289851
|
- |
|
gwos
|
groundwork_monitor
|
cgi-bin/performance/perfchart.cgi in the Performance component in GroundWork Monitor Enterprise 6.7.0 does not properly restrict XML content, which allows remote attackers to execute arbitrary comman…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3506
|
2024-11-21 10:53 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289852
|
- |
|
gwos
|
groundwork_monitor
|
The Nagios-App component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to bypass intended access restrictions via a direct request for a (1) log file or (2) configuration f…
|
CWE-255
Credentials Management
|
CVE-2013-3505
|
2024-11-21 10:53 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289853
|
- |
|
gwos
|
groundwork_monitor
|
Directory traversal vulnerability in monarch.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to overwrite arbitrary files by leveraging access to…
|
CWE-22
Path Traversal
|
CVE-2013-3504
|
2024-11-21 10:53 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289854
|
- |
|
gwos
|
groundwork_monitor
|
The Profile Importer feature in monarch.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to read arbitrary files via an XML document containing an…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3503
|
2024-11-21 10:53 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289855
|
- |
|
gwos
|
groundwork_monitor
|
monarch_scan.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to execute arbitrary commands, and consequently obtain sensitive information, by lev…
|
CWE-255
Credentials Management
|
CVE-2013-3502
|
2024-11-21 10:53 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289856
|
- |
|
gwos
|
groundwork_monitor
|
Multiple cross-site scripting (XSS) vulnerabilities in GroundWork Monitor Enterprise 6.7.0 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the foundation-weba…
|
CWE-79
Cross-site Scripting
|
CVE-2013-3501
|
2024-11-21 10:53 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289857
|
- |
|
gwos
|
groundwork_monitor
|
The Foundation webapp admin interface in GroundWork Monitor Enterprise 6.7.0 uses the nagios account as the owner of writable files under /usr/local/groundwork, which allows context-dependent attacke…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3500
|
2024-11-21 10:53 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289858
|
- |
|
gwos
|
groundwork_monitor
|
GroundWork Monitor Enterprise 6.7.0 performs authentication on the basis of the HTTP Referer header, which allows remote attackers to obtain administrative privileges or access files via a crafted he…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3499
|
2024-11-21 10:53 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289859
|
- |
|
joomla
|
joomla\!
|
Cross-site scripting (XSS) vulnerability in the highlighter plugin in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 allows remote attackers to inject arbitrary web script or HTML via unspecified…
|
CWE-79
Cross-site Scripting
|
CVE-2013-3267
|
2024-11-21 10:53 |
2013-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289860
|
- |
|
joomla
|
joomla\!
|
plugins/system/remember/remember.php in Joomla! 2.5.x before 2.5.10 and 3.0.x before 3.0.4 does not properly handle an object obtained by unserializing a cookie, which allows remote authenticated use…
|
CWE-20
Improper Input Validation
|
CVE-2013-3242
|
2024-11-21 10:53 |
2013-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|