259201
|
- |
|
wordpress
|
wordpress
|
WordPress before 3.6.1 does not properly validate URLs before use in an HTTP redirect, which allows remote attackers to bypass intended redirection restrictions via a crafted string.
|
CWE-20
Improper Input Validation
|
CVE-2013-4339
|
2013-12-31 13:25 |
2013-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259202
|
- |
|
hp
|
color_laserjet_3000 color_laserjet_3800 color_laserjet_4700 color_laserjet_4730_mfp color_laserjet_5550 color_laserjet_9500_mfp color_laserjet_cm6030_mfp color_laserjet_cm6040_mf…
|
Directory traversal vulnerability in the PostScript Interpreter, as used on the HP LaserJet 4xxx, 5200, 90xx, M30xx, M4345, M50xx, M90xx, P3005, and P4xxx; LaserJet Enterprise P3015; Color LaserJet 3…
|
NVD-CWE-noinfo
|
CVE-2012-5221
|
2013-12-31 13:19 |
2013-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259203
|
- |
|
wordpress
|
wordpress
|
Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of a…
|
CWE-352
Origin Validation Error
|
CVE-2013-7233
|
2013-12-31 10:42 |
2013-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259204
|
- |
|
adtran
|
aos netvanta_7060 netvanta_7100
|
Cross-site scripting (XSS) vulnerability in the GUI login page in ADTRAN AOS before R10.8.1 on the NetVanta 7100 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2013-5210
|
2013-12-31 10:34 |
2013-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259205
|
- |
|
hot
|
hotbox_router_firmware hotbox_router
|
goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST data.
|
CWE-20
Improper Input Validation
|
CVE-2013-5220
|
2013-12-31 04:29 |
2013-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259206
|
- |
|
hot
|
hotbox_router_firmware hotbox_router
|
Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not…
|
CWE-79
Cross-site Scripting
|
CVE-2013-5218
|
2013-12-31 04:27 |
2013-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259207
|
- |
|
hot
|
hotbox_router_firmware hotbox_router
|
Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a request for /etc/pass…
|
CWE-22
Path Traversal
|
CVE-2013-5219
|
2013-12-31 04:26 |
2013-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259208
|
- |
|
hot
|
hotbox_router_firmware hotbox_router
|
Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of administrators for re…
|
CWE-352
Origin Validation Error
|
CVE-2013-5039
|
2013-12-31 04:25 |
2013-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259209
|
- |
|
hot
|
hotbox_router_firmware hotbox_router
|
The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session.
|
CWE-287
Improper Authentication
|
CVE-2013-5038
|
2013-12-31 04:14 |
2013-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
259210
|
- |
|
hot
|
hotbox_router_firmware hotbox_router
|
The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers to obtain the WPA or WPA2 pre-shared key via EAP messages.
|
CWE-255
Credentials Management
|
CVE-2013-5037
|
2013-12-31 04:12 |
2013-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|