258281
|
- |
|
sophos
|
web_appliance_firmware web_appliance
|
Sophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip parameter to the Block page, when using the user_workstation va…
|
CWE-78
OS Command
|
CVE-2013-2642
|
2014-03-19 22:54 |
2014-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258282
|
- |
|
sophos
|
web_appliance_firmware web_appliance
|
Directory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files via the id parameter.
|
CWE-22
Path Traversal
|
CVE-2013-2641
|
2014-03-19 22:48 |
2014-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258283
|
- |
|
yumenomachi
|
demaecan
|
The Demaecan application 2.1.0 and earlier for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information …
|
CWE-310
Cryptographic Issues
|
CVE-2014-1976
|
2014-03-19 01:05 |
2014-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258284
|
- |
|
owncloud
|
owncloud
|
The configuration loader in ownCloud 5.0.x before 5.0.6 allows remote attackers to obtain CSRF tokens and other sensitive information by reading an unspecified JavaScript file.
|
CWE-200
Information Exposure
|
CVE-2013-2086
|
2014-03-18 00:43 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258285
|
- |
|
owncloud
|
owncloud
|
The login page (aka index.php) in ownCloud before 5.0.6 does not disable the autocomplete setting for the password parameter, which makes it easier for physically proximate attackers to guess the pas…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2047
|
2014-03-18 00:37 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258286
|
- |
|
owncloud
|
owncloud
|
Incomplete blacklist vulnerability in ownCloud before 5.0.6 allows remote authenticated users to execute arbitrary PHP code by uploading a crafted file, then accessing it via a direct request to the …
|
NVD-CWE-Other
|
CVE-2013-2089
|
2014-03-18 00:36 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258287
|
- |
|
owncloud
|
owncloud
|
Per: https://cwe.mitre.org/data/definitions/184.html
"CWE-184: Incomplete Blacklist"
|
NVD-CWE-Other
|
CVE-2013-2089
|
2014-03-18 00:36 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258288
|
- |
|
owncloud
|
owncloud
|
ownCloud before 5.0.6 does not properly check permissions, which allows remote authenticated users to execute arbitrary API commands via unspecified vectors. NOTE: this can be leveraged using CSRF t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2048
|
2014-03-18 00:26 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258289
|
- |
|
owncloud
|
owncloud
|
Open redirect vulnerability in the Login Page (index.php) in ownCloud before 5.0.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redir…
|
CWE-20
Improper Input Validation
|
CVE-2013-2044
|
2014-03-18 00:24 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258290
|
- |
|
owncloud
|
owncloud
|
apps/calendar/ajax/events.php in ownCloud before 4.5.11 and 5.x before 5.0.6 does not properly check the ownership of a calendar, which allows remote authenticated users to download arbitrary calenda…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-2043
|
2014-03-18 00:22 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|