260881
|
- |
|
cisco
|
nx-os
|
The encryption functionality in the Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication component in Cisco NX-OS on the Nexus 1000V does not properly authenticate VSM/VEM p…
|
CWE-287
Improper Authentication
|
CVE-2013-1209
|
2013-05-30 22:30 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260882
|
- |
|
cisco
|
nx-os
|
The encryption functionality in Cisco NX-OS on the Nexus 1000V does not properly handle Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication, which allows remote attackers t…
|
CWE-310
Cryptographic Issues
|
CVE-2013-1208
|
2013-05-30 22:26 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260883
|
- |
|
lockon
|
ec-cube
|
Cross-site scripting (XSS) vulnerability in the shopping-cart screen in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2312
|
2013-05-30 13:00 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260884
|
- |
|
lockon
|
ec-cube
|
data/class/pages/forgot/LC_Page_Forgot.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 does not properly validate the input to the password reminder function, which allows remote attackers to obtain …
|
CWE-20
Improper Input Validation
|
CVE-2013-2315
|
2013-05-30 13:00 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260885
|
- |
|
gentoo
|
webmin
|
Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.
|
CWE-20
Improper Input Validation
|
CVE-2012-2981
|
2013-05-30 12:16 |
2012-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260886
|
- |
|
gentoo
|
webmin
|
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
|
NVD-CWE-Other
|
CVE-2012-2982
|
2013-05-30 12:16 |
2012-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260887
|
- |
|
gentoo
|
webmin
|
file/edit_html.cgi in Webmin 1.590 and earlier does not perform an authorization check before showing a file's unedited contents, which allows remote attackers to read arbitrary files via the file fi…
|
CWE-287
Improper Authentication
|
CVE-2012-2983
|
2013-05-30 12:16 |
2012-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260888
|
- |
|
ibm
|
infosphere_optim_data_growth_for_oracle_e-business_suite
|
IBM InfoSphere Optim Data Growth for Oracle E-Business Suite 6.x, 7.x, and 9.x before 9.1.0.3 relies on the MD5 algorithm for signatures in X.509 certificates, which makes it easier for man-in-the-mi…
|
CWE-310
Cryptographic Issues
|
CVE-2013-2953
|
2013-05-28 13:00 |
2013-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260889
|
- |
|
cisco
|
webex
|
Cisco WebEx 4.1 on iOS does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middl…
|
CWE-20
Improper Input Validation
|
CVE-2012-6399
|
2013-05-28 13:00 |
2013-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260890
|
- |
|
hp
|
business_service_management
|
HP Business Service Management (BSM) 9.12 does not properly restrict the uploading of .war files, which allows remote attackers to execute arbitrary JSP code within the JBOSS Application Server compo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-2561
|
2013-05-25 12:11 |
2012-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|