258831
|
- |
|
almanah_project
|
almanah
|
Almanah Diary 0.9.0 and 0.10.0 does not encrypt the database when closed, which allows local users to obtain sensitive information by reading the database.
|
CWE-310
Cryptographic Issues
|
CVE-2013-1853
|
2014-02-25 11:44 |
2014-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258832
|
- |
|
opsview
|
opsview
|
Cross-site request forgery (CSRF) vulnerability in Opsview before 4.4.2 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
|
CWE-352
Origin Validation Error
|
CVE-2013-7256
|
2014-02-25 11:17 |
2014-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258833
|
- |
|
cs-cart
|
cs-cart
|
Multiple cross-site scripting (XSS) vulnerabilities in CS-Cart before 4.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) settings_file or (2) data_file parameter to (a) a…
|
CWE-79
Cross-site Scripting
|
CVE-2013-7317
|
2014-02-25 11:14 |
2014-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258834
|
- |
|
aphpkb
|
aphpkb
|
Multiple cross-site scripting (XSS) vulnerabilities in register.php in Andy's PHP Knowledgebase (Aphpkb) before 0.95.8 allow remote attackers to inject arbitrary web script or HTML via the (1) first_…
|
CWE-79
Cross-site Scripting
|
CVE-2013-7289
|
2014-02-25 11:01 |
2014-01-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258835
|
- |
|
google
|
chrome
|
Google Chrome through 32.0.1700.23 on Android allows remote attackers to spoof the address bar via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2013-6642
|
2014-02-25 10:55 |
2014-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258836
|
- |
|
cru-inc
|
ditto_forensic_fieldstation_firmware ditto_forensic_fieldstation
|
The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allows remote attackers to gain privileges.
|
CWE-255
Credentials Management
|
CVE-2013-6884
|
2014-02-25 10:44 |
2014-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258837
|
- |
|
wordpress
|
wordpress
|
wp-admin/includes/class-wp-posts-list-table.php in WordPress before 3.3.3 does not properly restrict excerpt-view access, which allows remote authenticated users to obtain sensitive information by vi…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6635
|
2014-02-25 10:38 |
2014-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258838
|
- |
|
wordpress
|
wordpress
|
wp-admin/media-upload.php in WordPress before 3.3.3 allows remote attackers to obtain sensitive information or bypass intended media-attachment restrictions via a post_id value.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2012-6634
|
2014-02-25 10:37 |
2014-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258839
|
- |
|
wordpress
|
wordpress
|
Cross-site scripting (XSS) vulnerability in wp-includes/default-filters.php in WordPress before 3.3.3 allows remote attackers to inject arbitrary web script or HTML via an editable slug field.
|
CWE-79
Cross-site Scripting
|
CVE-2012-6633
|
2014-02-25 10:36 |
2014-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258840
|
- |
|
aloaha
|
aloaha_pdf_suite_free aloahapdfviewer
|
Stack-based buffer overflow in AloahaPDFViewer 5.0.0.7 and earlier in Aloaha PDF Suite FREE allows remote attackers to execute arbitrary code via a crafted PDF file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-4978
|
2014-02-25 10:13 |
2014-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|