259631
|
- |
|
lockon
|
ec-cube
|
Cross-site scripting (XSS) vulnerability in the displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 through 2.11.5 allows remote attackers to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2013-5992
|
2013-11-21 23:36 |
2013-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259632
|
- |
|
lockon
|
ec-cube
|
Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.0 allows remote attackers to hijack the authentication of arbitrary users via unspecified vectors related to refu…
|
CWE-352
Origin Validation Error
|
CVE-2013-5993
|
2013-11-21 23:35 |
2013-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259633
|
- |
|
lockon
|
ec-cube
|
data/class/pages/mypage/LC_Page_Mypage_DeliveryAddr.php in LOCKON EC-CUBE 2.11.2 through 2.13.0 allows remote attackers to obtain sensitive information via a direct request, which reveals the full pa…
|
CWE-200
Information Exposure
|
CVE-2013-5994
|
2013-11-21 23:35 |
2013-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259634
|
- |
|
cisco
|
nexus_1000v
|
The license-installation module on the Cisco Nexus 1000V switch 4.2(1)SV1(5.2b) and earlier for VMware vSphere, Cisco Nexus 1000V switch 5.2(1)SM1(5.1) for Microsoft Hyper-V, and Cisco Virtual Securi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-5556
|
2013-11-21 02:40 |
2013-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259635
|
- |
|
dlink
|
dir865l_firmware dir865l
|
Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DIR865L router (Rev. A1) with firmware before 1.05b07 allow remote attackers to hijack the authentication of administrators for re…
|
CWE-352
Origin Validation Error
|
CVE-2013-3095
|
2013-11-21 02:39 |
2013-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259636
|
- |
|
collectiveaccess
|
pawtucket providence
|
Cross-site scripting (XSS) vulnerability in CollectiveAccess Providence and Pawtucket before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-4507
|
2013-11-21 02:39 |
2013-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259637
|
- |
|
fortinet
|
fortianalyzer_firmware fortianalyzer-1000d fortianalyzer-2000b fortianalyzer-200d fortianalyzer-3000d fortianalyzer-300d fortianalyzer-4000b
|
cgi-bin/module//sysmanager/admin/SYSAdminUserDialog in Fortinet FortiAnalyzer before 5.0.5 does not properly validate the csrf_token parameter, which allows remote attackers to perform cross-site req…
|
CWE-352
Origin Validation Error
|
CVE-2013-6826
|
2013-11-21 02:10 |
2013-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259638
|
- |
|
zkoss
|
zk_framework
|
Cross-site scripting (XSS) vulnerability in ZK Framework before 5.0.13 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-5966
|
2013-11-21 00:23 |
2013-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259639
|
- |
|
tryton
|
tryton
|
Directory traversal vulnerability in the client in Tryton 3.0.0, as distributed before 20131104 and earlier, allows remote servers to write arbitrary files via path separators in the extension of a r…
|
CWE-22
Path Traversal
|
CVE-2013-4510
|
2013-11-20 09:31 |
2013-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259640
|
- |
|
apple
|
iphone_os
|
The App Store component in Apple iOS before 7.0.4 does not properly enforce an intended transaction-time password requirement, which allows local users to complete a (1) App purchase or (2) In-App pu…
|
CWE-255
Credentials Management
|
CVE-2013-5193
|
2013-11-20 09:24 |
2013-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|