|
288961
|
6.1 |
MEDIUM
Network
|
puppet
|
puppet_enterprise
|
Puppet Enterprise before 3.0.1 allows remote attackers to (1) conduct clickjacking attacks via unspecified vectors related to the console, and (2) conduct cross-site scripting (XSS) attacks via unspe…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4968
|
2024-11-21 10:56 |
2019-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288962
|
9.8 |
CRITICAL
Network
|
netgear
|
wnr3500u_firmware wnr3500l_firmware
|
Symlink Traversal vulnerability in NETGEAR WNR3500U and WNR3500L due to misconfiguration in the SMB service.
|
CWE-22
Path Traversal
|
CVE-2013-4657
|
2024-11-21 10:56 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288963
|
9.8 |
CRITICAL
Network
|
asus
|
rt-ac66u_firmware rt-n56u_firmware
|
Symlink Traversal vulnerability in ASUS RT-AC66U and RT-N56U due to misconfiguration in the SMB service.
|
CWE-22
Path Traversal
|
CVE-2013-4656
|
2024-11-21 10:56 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288964
|
8.1 |
HIGH
Network
|
sensiolabs fedoraproject redhat
|
symfony fedora enterprise_linux
|
php-symfony2-Validator has loss of information during serialization
|
CWE-20
Improper Input Validation
|
CVE-2013-4751
|
2024-11-21 10:56 |
2019-11-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288965
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wdr4300_firmware
|
TP-Link TL-WDR4300 version 3.13.31 has multiple CSRF vulnerabilities.
|
CWE-352
Origin Validation Error
|
CVE-2013-4848
|
2024-11-21 10:56 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288966
|
9.8 |
CRITICAL
Network
|
linksys
|
ea6500_firmware
|
Linksys EA6500 has SMB Symlink Traversal allowing symbolic links to be created to locations outside of the Samba share.
|
CWE-22
Path Traversal
|
CVE-2013-4658
|
2024-11-21 10:56 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288967
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-865l_firmware
|
D-Link DIR-865L has PHP File Inclusion in the router xml file.
|
CWE-91
Blind XPath Injection
|
CVE-2013-4857
|
2024-11-21 10:56 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288968
|
6.5 |
MEDIUM
Adjacent
|
dlink
|
dir-865l_firmware
|
D-Link DIR-865L has Information Disclosure.
|
CWE-200
Information Exposure
|
CVE-2013-4856
|
2024-11-21 10:56 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288969
|
8.8 |
HIGH
Adjacent
|
dlink
|
dir-865l_firmware
|
D-Link DIR-865L has SMB Symlink Traversal due to misconfiguration in the SMB service allowing symbolic links to be created to locations outside of the Samba share.
|
CWE-22
Path Traversal
|
CVE-2013-4855
|
2024-11-21 10:56 |
2019-10-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288970
|
6.1 |
MEDIUM
Network
|
codeigniter
|
codeigniter
|
The xss_clean function in CodeIgniter before 2.1.4 might allow remote attackers to bypass an intended protection mechanism and conduct cross-site scripting (XSS) attacks via an unclosed HTML tag.
|
CWE-79
Cross-site Scripting
|
CVE-2013-4891
|
2024-11-21 10:56 |
2018-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|