260871
|
- |
|
cisco
|
prime_infrastructure
|
Cross-site scripting (XSS) vulnerability in the wireless configuration module in Cisco Prime Infrastructure allows remote attackers to inject arbitrary web script or HTML via an SSID that is not prop…
|
CWE-79
Cross-site Scripting
|
CVE-2013-1247
|
2013-06-3 13:00 |
2013-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260872
|
- |
|
tibco
|
silver_mobile
|
The server in TIBCO Silver Mobile 1.1.0 does not properly verify access to the administrator role before executing a command, which allows authenticated users to gain privileges via unspecified vecto…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3315
|
2013-06-3 13:00 |
2013-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260873
|
- |
|
algisinfo
|
aicontactsafe
|
Cross-site scripting (XSS) vulnerability in the aiContactSafe component before 2.0.21 for Joomla! allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-3719
|
2013-06-3 13:00 |
2013-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260874
|
- |
|
microsys
|
promotic
|
Directory traversal vulnerability in the PmWebDir object in the web server in MICROSYS PROMOTIC before 8.1.5 allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2011-4518
|
2013-06-3 13:00 |
2013-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260875
|
- |
|
psychostats
|
psychostats
|
SQL injection vulnerability in awards.php in PsychoStats 3.2.2b allows remote attackers to execute arbitrary SQL commands via the d parameter.
|
CWE-89
SQL Injection
|
CVE-2013-3721
|
2013-05-31 21:20 |
2013-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260876
|
- |
|
google lg
|
android optimus_g_e973
|
The LG Hidden Menu component for Android on the LG Optimus G E973 allows physically proximate attackers to execute arbitrary commands by entering USB Debugging mode, using Android Debug Bridge (adb) …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3666
|
2013-05-31 13:00 |
2013-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260877
|
- |
|
siemens
|
wincc_tia_portal
|
Siemens WinCC (TIA Portal) 11 uses a reversible algorithm for storing HMI web-application passwords in world-readable and world-writable files, which allows local users to obtain sensitive informatio…
|
CWE-255
Credentials Management
|
CVE-2011-4515
|
2013-05-31 13:00 |
2013-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260878
|
- |
|
siemens
|
wincc_tia_portal
|
Per http://ics-cert.us-cert.gov/pdf/ICSA-13-079-03.pdf
INSECURE PASWORD STORAGE
User credentials for the HMI’s Web application are stored within the HMI’s system. These data are obfuscated in a r…
|
CWE-255
Credentials Management
|
CVE-2011-4515
|
2013-05-31 13:00 |
2013-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260879
|
- |
|
cisco
|
nx-os
|
Cisco NX-OS on the Nexus 1000V does not properly handle authentication for Virtual Ethernet Module (VEM) to Virtual Supervisor Module (VSM) communication, which allows remote attackers to obtain VEM …
|
CWE-287
Improper Authentication
|
CVE-2013-1211
|
2013-05-30 22:43 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260880
|
- |
|
cisco
|
nx-os
|
Array index error in the Virtual Ethernet Module (VEM) kernel driver for VMware ESXi in Cisco NX-OS on the Nexus 1000V, when STUN debugging is enabled, allows remote attackers to cause a denial of se…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-1210
|
2013-05-30 22:36 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|