260431
|
- |
|
cisco
|
unified_customer_voice_portal
|
The log viewer in Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 does not properly validate an unspecified parameter, which allows remote attackers to read arbitrary files via …
|
CWE-20
Improper Input Validation
|
CVE-2013-1223
|
2013-05-9 21:31 |
2013-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260432
|
- |
|
cisco
|
unified_customer_voice_portal
|
Cisco Unified Customer Voice Portal (CVP) Software before 9.0.1 ES 11 allows remote attackers to read arbitrary files via a Resource Manager (1) HTTP or (2) HTTPS request containing an external entit…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-1225
|
2013-05-9 21:31 |
2013-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260433
|
- |
|
softbanktech
|
online_service_gate
|
The (1) OWA Helper and (2) OSG Lite programs in SoftBank Online Service Gate allow remote authenticated users to discover their own passwords, and consequently bypass an Office 365 restriction, via u…
|
CWE-200
Information Exposure
|
CVE-2013-2308
|
2013-05-9 21:31 |
2013-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260434
|
- |
|
cisco
|
ios 1921_integrated_services_router 1941_integrated_services_router 1941w_integrated_services_router 2901_integrated_services_router 2911_integrated_services_router 2921_integrated_…
|
The ISM module in Cisco IOS on ISR G2 routers does not properly handle authentication-header packets, which allows remote authenticated users to cause a denial of service (module reload) via a series…
|
CWE-287
Improper Authentication
|
CVE-2013-1241
|
2013-05-8 21:09 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260435
|
- |
|
gwos
|
groundwork_monitor
|
The Foundation webapp admin interface in GroundWork Monitor Enterprise 6.7.0 uses the nagios account as the owner of writable files under /usr/local/groundwork, which allows context-dependent attacke…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3500
|
2013-05-8 21:09 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260436
|
- |
|
gwos
|
groundwork_monitor
|
Multiple cross-site scripting (XSS) vulnerabilities in GroundWork Monitor Enterprise 6.7.0 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) the foundation-weba…
|
CWE-79
Cross-site Scripting
|
CVE-2013-3501
|
2013-05-8 21:09 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260437
|
- |
|
gwos
|
groundwork_monitor
|
The Profile Importer feature in monarch.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to read arbitrary files via an XML document containing an…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3503
|
2013-05-8 21:09 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260438
|
- |
|
gwos
|
groundwork_monitor
|
Directory traversal vulnerability in monarch.cgi in the MONARCH component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to overwrite arbitrary files by leveraging access to…
|
CWE-22
Path Traversal
|
CVE-2013-3504
|
2013-05-8 21:09 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260439
|
- |
|
gwos
|
groundwork_monitor
|
cgi-bin/performance/perfchart.cgi in the Performance component in GroundWork Monitor Enterprise 6.7.0 does not properly restrict XML content, which allows remote attackers to execute arbitrary comman…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-3506
|
2013-05-8 21:09 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260440
|
- |
|
gwos
|
groundwork_monitor
|
The NeDi component in GroundWork Monitor Enterprise 6.7.0 allows remote authenticated users to obtain sensitive information via a direct request for (1) a configuration file, (2) a database dump, or …
|
CWE-200
Information Exposure
|
CVE-2013-3507
|
2013-05-8 21:09 |
2013-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|