259701
|
- |
|
tiki
|
tikiwiki_cms\/groupware
|
SQL injection vulnerability in Tiki Wiki CMS Groupware 6 LTS before 6.13LTS, 9 LTS before 9.7LTS, 10.x before 10.4, and 11.x before 11.1 allows remote attackers to execute arbitrary SQL commands via …
|
CWE-89
SQL Injection
|
CVE-2013-4715
|
2013-11-7 09:51 |
2013-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259702
|
- |
|
cisco
|
prime_central_for_hosted_collaboration_solution
|
The ITM web server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (temporary HTTP service outage) via a flood of TCP packets, aka …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-5562
|
2013-11-7 09:50 |
2013-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259703
|
- |
|
cisco
|
security_monitoring_analysis_and_response_system
|
Cross-site scripting (XSS) vulnerability in Query/NewQueryResult.jsp in Cisco Security Monitoring, Analysis and Response System (CS-MARS) allows remote attackers to inject arbitrary web script or HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5563
|
2013-11-7 09:47 |
2013-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259704
|
- |
|
ajaxplorer
|
ajaxplorer
|
Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read arbitrary files via a ../%00 (dot dot backslash encoded null byte) i…
|
CWE-22
Path Traversal
|
CVE-2013-5688
|
2013-11-7 03:55 |
2013-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259705
|
- |
|
emc
|
documentum_eroom
|
Multiple cross-site scripting (XSS) vulnerabilities in EMC Documentum eRoom before 7.4.4 P11 allow remote attackers to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2013-3286
|
2013-11-7 03:47 |
2013-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259706
|
- |
|
smackcoders
|
wp_ultimate_email_marketer_plugin
|
The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2) campaign/editCampaign.php, which allows remote attackers …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3264
|
2013-11-6 23:55 |
2013-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259707
|
- |
|
saltstack
|
salt
|
The salt master in Salt (aka SaltStack) 0.11.0 through 0.17.0 does not properly drop group privileges, which makes it easier for remote attackers to gain privileges.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6617
|
2013-11-6 23:36 |
2013-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259708
|
- |
|
cisco
|
prime_central_for_hosted_collaboration_solution
|
The Java process in the Impact server in Cisco Prime Central for Hosted Collaboration Solution (HCS) allows remote attackers to cause a denial of service (process crash) via a flood of TCP packets, a…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-5564
|
2013-11-6 23:04 |
2013-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259709
|
- |
|
thoughtbot
|
cocaine
|
The Cocaine gem 0.4.0 through 0.5.2 for Ruby allows context-dependent attackers to execute arbitrary commands via a crafted has object, related to recursive variable interpolation.
|
CWE-78
OS Command
|
CVE-2013-4457
|
2013-11-6 00:21 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259710
|
- |
|
nas4free
|
nas4free
|
NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execute Command" feature. NOTE: this issue might not b…
|
CWE-94
Code Injection
|
CVE-2013-3631
|
2013-11-5 23:56 |
2013-11-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|