259681
|
- |
|
xymon
|
xymon
|
Directory traversal vulnerability in the trend-data daemon (xymond_rrd) in Xymon 4.x before 4.3.12 allows remote attackers to delete arbitrary files via a .. (dot dot) in the host name in a "drophost…
|
CWE-22
Path Traversal
|
CVE-2013-4173
|
2013-10-16 00:21 |
2013-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259682
|
- |
|
cmsmadesimple
|
cms_made_simple
|
Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) before 1.11.7 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-4167
|
2013-10-15 23:54 |
2013-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259683
|
- |
|
status
|
statusnet
|
Multiple SQL injection vulnerabilities in StatusNet 1.0 before 1.0.2 and 1.1.0 allow remote attackers to execute arbitrary SQL commands via vectors related to user lists and "a particular tag format."
|
CWE-89
SQL Injection
|
CVE-2013-4137
|
2013-10-15 23:42 |
2013-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259684
|
- |
|
ovislink
|
airlive_od-2025hd airlive_od-2060hd airlive_poe100hd airlive_poe200hd airlive_poe250hd airlive_poe2600hd
|
AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models use cleartext to store sensitive information, which allows attackers to obtain passwo…
|
CWE-310
Cryptographic Issues
|
CVE-2013-3687
|
2013-10-15 23:20 |
2013-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259685
|
- |
|
ovislink
|
airlive_wl2600cam
|
cgi-bin/operator/param in AirLive WL2600CAM and possibly other camera models allows remote attackers to obtain the administrator password via a list action.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3686
|
2013-10-15 23:15 |
2013-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259686
|
- |
|
tp-link
|
tl-sc3130 tl-sc3130g tl-sc3171 tl-sc3171g lm_firmware
|
cgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to modify the fir…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2581
|
2013-10-15 23:12 |
2013-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259687
|
- |
|
tp-link
|
tl-sc3130 tl-sc3130g tl-sc3171 tl-sc3171g lm_firmware
|
TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty password for the hardcoded "qmik" account, which allow…
|
CWE-255
Credentials Management
|
CVE-2013-2579
|
2013-10-15 23:11 |
2013-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259688
|
- |
|
tp-link
|
tl-sc3130 tl-sc3130g tl-sc3171 tl-sc3171g lm_firmware
|
Unrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6, all…
|
NVD-CWE-Other
|
CVE-2013-2580
|
2013-10-15 22:23 |
2013-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259689
|
- |
|
tp-link
|
tl-sc3130 tl-sc3130g tl-sc3171 tl-sc3171g lm_firmware
|
Per: http://cwe.mitre.org/data/definitions/434.html
'CWE-434: Unrestricted Upload of File with Dangerous Type'
|
NVD-CWE-Other
|
CVE-2013-2580
|
2013-10-15 22:23 |
2013-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259690
|
- |
|
tp-link
|
tl-sc3130 tl-sc3130g tl-sc3171 tl-sc3171g lm_firmware
|
cgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 allows remote attackers to execute arbitr…
|
CWE-78
OS Command
|
CVE-2013-2578
|
2013-10-15 22:13 |
2013-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|