|
291171
|
- |
|
spip
|
spip
|
SPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial control" via vectors related to ecrire/inc/filtres.php.
|
NVD-CWE-noinfo
|
CVE-2013-2118
|
2024-11-21 10:51 |
2013-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291172
|
- |
|
openstack
|
havana grizzly folsom
|
OpenStack Compute (Nova) Folsom, Grizzly, and Havana does not verify the virtual size of a QCOW2 image, which allows local users to cause a denial of service (host file system disk consumption) by cr…
|
CWE-399
Resource Management Errors
|
CVE-2013-2096
|
2024-11-21 10:51 |
2013-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291173
|
- |
|
wordpress
|
wordpress
|
The default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote attackers to bypass the Same Origin Policy and conduct cross-si…
|
CWE-79 CWE-16
Cross-site Scripting Configuration
|
CVE-2013-2205
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291174
|
- |
|
wordpress tinymce
|
wordpress media
|
moxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not consider the presence of a # (pound sign) character during extracti…
|
CWE-20
Improper Input Validation
|
CVE-2013-2204
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291175
|
- |
|
wordpress
|
wordpress
|
WordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an invalid upload request, which reveals the absolute path in an X…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2203
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291176
|
- |
|
wordpress
|
wordpress
|
WordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity declaration in conjunction with an entity reference, related t…
|
CWE-200
Information Exposure
|
CVE-2013-2202
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291177
|
- |
|
wordpress
|
wordpress
|
Multiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) uploads of media files, (2) editi…
|
CWE-79
Cross-site Scripting
|
CVE-2013-2201
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291178
|
- |
|
wordpress
|
wordpress
|
WordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended restrictions on publishing and authorship reassignment via unspeci…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2200
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291179
|
- |
|
wordpress
|
wordpress
|
The HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related to a Server-Side Request Forgery (SSRF) issue, a similar vuln…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2199
|
2024-11-21 10:51 |
2013-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291180
|
- |
|
hp
|
procurve_switch h3c_switch h3c_ethernet_switch h3c_router 3com_router procurve_router 3com_switch h3c_routing_switch h3c_processing_module h3c_high_performance_main_process…
|
Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and s…
|
NVD-CWE-noinfo
|
CVE-2013-2341
|
2024-11-21 10:51 |
2013-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|