258441
|
- |
|
thoughtbot
|
cocaine
|
The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, related to recursive variable interpolation.
|
CWE-78
OS Command
|
CVE-2013-4457
|
2013-11-6 00:21 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258442
|
- |
|
nas4free
|
nas4free
|
NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execute Command" feature. NOTE: this issue might not b…
|
CWE-94
Code Injection
|
CVE-2013-3631
|
2013-11-5 23:56 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258443
|
- |
|
novell
|
zenworks_configuration_management
|
The ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows attackers to conduct cross-frame scripting attacks via unknown vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-6344
|
2013-11-5 09:04 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258444
|
- |
|
novell
|
zenworks_configuration_management
|
Unspecified vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 has unknown impact and attack vectors related to an "Application Exception."
|
NVD-CWE-noinfo
|
CVE-2013-6345
|
2013-11-5 09:03 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258445
|
- |
|
novell
|
zenworks_configuration_management
|
Cross-site request forgery (CSRF) vulnerability in the ZCC page in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack the authentication of unspecified vic…
|
CWE-352
Origin Validation Error
|
CVE-2013-6346
|
2013-11-5 08:59 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258446
|
- |
|
novell
|
zenworks_configuration_management
|
Session fixation vulnerability in Novell ZENworks Configuration Management (ZCM) before 11.2.4 allows remote attackers to hijack web sessions via unspecified vectors.
|
CWE-287
Improper Authentication
|
CVE-2013-6347
|
2013-11-5 08:58 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258447
|
- |
|
mcafee
|
email_gateway
|
McAfee Email Gateway (MEG) 7.0 before 7.0.4 and 7.5 before 7.5.1 allows remote authenticated users to execute arbitrary commands via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2013-6349
|
2013-11-5 08:53 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258448
|
- |
|
ingo_renner
|
apache_solr
|
Unspecified vulnerability in the Apache Solr for TYPO3 (solr) extension before 2.8.3 for TYPO3 has unknown impact and remote attack vectors, related to "Insecure Unserialize."
|
NVD-CWE-noinfo
|
CVE-2013-6288
|
2013-11-3 12:35 |
2013-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258449
|
- |
|
ingo_renner
|
apache_solr
|
Cross-site scripting (XSS) vulnerability in the Apache Solr for TYPO3 (solr) extension before 2.8.3 for TYPO3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-6289
|
2013-11-3 12:35 |
2013-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258450
|
- |
|
huawei
|
ar_1200 ar_150 ar_200 ar_2200 ar_3200
|
Stack-based buffer overflow on Huawei AR 150, 200, 1200, 2200, and 3200 routers, when SNMPv3 debugging is enabled, allows remote attackers to execute arbitrary code via malformed SNMPv3 requests.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-4630
|
2013-11-3 12:34 |
2013-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|