260561
|
- |
|
siemens
|
simatic_pcs7 wincc
|
SQL injection vulnerability in the login screen in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, allows remote attackers to e…
|
CWE-89
SQL Injection
|
CVE-2013-3957
|
2013-06-17 13:00 |
2013-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260562
|
- |
|
siemens
|
simatic_pcs7 wincc
|
The login implementation in the Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, has a hardcoded account, which makes it easier for …
|
CWE-255
Credentials Management
|
CVE-2013-3958
|
2013-06-17 13:00 |
2013-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260563
|
- |
|
siemens
|
simatic_pcs7 wincc
|
The Web Navigator in Siemens WinCC before 7.2 Update 1, as used in SIMATIC PCS7 8.0 SP1 and earlier and other products, exhibits different behavior for NetBIOS user names depending on whether the use…
|
CWE-200
Information Exposure
|
CVE-2013-3959
|
2013-06-17 13:00 |
2013-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260564
|
- |
|
orchardproject
|
orchard
|
Cross-site scripting (XSS) vulnerability in the Orchard.Comments module in Orchard before 1.6.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-3645
|
2013-06-15 00:12 |
2013-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260565
|
- |
|
hp
|
insight_diagnostics
|
hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows remote attackers to include arbitrary hpdiags/front…
|
CWE-20
Improper Input Validation
|
CVE-2013-3575
|
2013-06-15 00:00 |
2013-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260566
|
- |
|
hp
|
insight_diagnostics
|
Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers to write data to arbitrary files via a full path…
|
CWE-20
Improper Input Validation
|
CVE-2013-3574
|
2013-06-14 23:59 |
2013-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260567
|
- |
|
cisco
|
video_surveillance_operations_manager
|
Open redirect vulnerability in the help page in Cisco Video Surveillance Operations Manager allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a crafted…
|
CWE-20
Improper Input Validation
|
CVE-2013-3376
|
2013-06-14 22:18 |
2013-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260568
|
- |
|
cisco
|
prime_central_for_hosted_collaboration_solution
|
Cross-site scripting (XSS) vulnerability in the portal page in Cisco Prime Central for Hosted Collaboration Solution allows remote attackers to inject arbitrary web script or HTML via a crafted URL, …
|
CWE-79
Cross-site Scripting
|
CVE-2013-3375
|
2013-06-14 22:10 |
2013-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260569
|
- |
|
hp
|
insight_diagnostics
|
HP Insight Diagnostics 9.4.0.4710 allows remote attackers to conduct unspecified injection attacks via unknown vectors.
|
CWE-20
Improper Input Validation
|
CVE-2013-3573
|
2013-06-14 22:07 |
2013-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260570
|
- |
|
juniper
|
junos_pulse_secure_access_service junos_pulse_access_control_service
|
Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS 7.0r2 through 7.0r8 and 7.1r1 through 7.1r5 and Junos Pulse Access Control Service (aka UAC) with UAC OS 4.1r1 through 4.1r5 includ…
|
CWE-310
Cryptographic Issues
|
CVE-2013-3970
|
2013-06-14 02:47 |
2013-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|