259551
|
- |
|
jahia
|
jahia_xcm
|
Jahia xCM before 6.6.2 does not include the HTTPOnly flag in a Set-Cookie header for the JSESSIONID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via …
|
CWE-200
Information Exposure
|
CVE-2013-4617
|
2013-11-29 22:38 |
2013-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259552
|
- |
|
jahia
|
jahia_xcm
|
Cross-site scripting (XSS) vulnerability in Jahia xCM before 6.6.2 allows remote authenticated users to inject arbitrary web script or HTML via the "about me" field.
|
CWE-79
Cross-site Scripting
|
CVE-2013-3920
|
2013-11-29 22:35 |
2013-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259553
|
- |
|
sybase
|
adaptive_server_enterprise
|
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to …
|
NVD-CWE-noinfo
|
CVE-2013-6860
|
2013-11-28 01:49 |
2013-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259554
|
- |
|
sybase
|
adaptive_server_enterprise
|
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows local users to obtain s…
|
NVD-CWE-noinfo
|
CVE-2013-6861
|
2013-11-28 01:45 |
2013-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259555
|
- |
|
sybase
|
adaptive_server_enterprise
|
Unspecified vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote attackers to cause a de…
|
NVD-CWE-noinfo
|
CVE-2013-6862
|
2013-11-28 01:44 |
2013-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259556
|
- |
|
sybase
|
adaptive_server_enterprise
|
SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to gain privileges via un…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-6863
|
2013-11-28 01:42 |
2013-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259557
|
- |
|
sybase
|
adaptive_server_enterprise
|
SAP Sybase Adaptive Server Enterprise (ASE) before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenticated users to execute arbitrary code via un…
|
CWE-94
Code Injection
|
CVE-2013-6866
|
2013-11-28 01:41 |
2013-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259558
|
- |
|
sybase
|
adaptive_server_enterprise
|
Directory traversal vulnerability in SAP Sybase Adaptive Server Enterprise (ASE) 15.0.3 before 15.0.3 ESD#4.3, 15.5 before 15.5 ESD#5.3, and 15.7 before 15.7 SP50 or 15.7 SP100 allows remote authenti…
|
CWE-22
Path Traversal
|
CVE-2013-6864
|
2013-11-28 01:40 |
2013-11-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259559
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in the ZeroRatedMobileAccess extension for MediaWiki 1.19.x before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to inject ar…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4573
|
2013-11-28 01:30 |
2013-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259560
|
- |
|
splunk
|
splunk
|
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-6870
|
2013-11-28 01:19 |
2013-11-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|