260671
|
- |
|
siemens
|
wincc_tia_portal
|
Siemens WinCC (TIA Portal) 11 uses a reversible algorithm for storing HMI web-application passwords in world-readable and world-writable files, which allows local users to obtain sensitive informatio…
|
CWE-255
Credentials Management
|
CVE-2011-4515
|
2013-05-31 13:00 |
2013-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260672
|
- |
|
siemens
|
wincc_tia_portal
|
Per http://ics-cert.us-cert.gov/pdf/ICSA-13-079-03.pdf
INSECURE PASWORD STORAGE
User credentials for the HMI’s Web application are stored within the HMI’s system. These data are obfuscated in a r…
|
CWE-255
Credentials Management
|
CVE-2011-4515
|
2013-05-31 13:00 |
2013-03-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260673
|
- |
|
cisco
|
nx-os
|
Cisco NX-OS on the Nexus 1000V does not properly handle authentication for Virtual Ethernet Module (VEM) to Virtual Supervisor Module (VSM) communication, which allows remote attackers to obtain VEM …
|
CWE-287
Improper Authentication
|
CVE-2013-1211
|
2013-05-30 22:43 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260674
|
- |
|
cisco
|
nx-os
|
Array index error in the Virtual Ethernet Module (VEM) kernel driver for VMware ESXi in Cisco NX-OS on the Nexus 1000V, when STUN debugging is enabled, allows remote attackers to cause a denial of se…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2013-1210
|
2013-05-30 22:36 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260675
|
- |
|
cisco
|
nx-os
|
The encryption functionality in the Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication component in Cisco NX-OS on the Nexus 1000V does not properly authenticate VSM/VEM p…
|
CWE-287
Improper Authentication
|
CVE-2013-1209
|
2013-05-30 22:30 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260676
|
- |
|
cisco
|
nx-os
|
The encryption functionality in Cisco NX-OS on the Nexus 1000V does not properly handle Virtual Supervisor Module (VSM) to Virtual Ethernet Module (VEM) communication, which allows remote attackers t…
|
CWE-310
Cryptographic Issues
|
CVE-2013-1208
|
2013-05-30 22:26 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260677
|
- |
|
lockon
|
ec-cube
|
Cross-site scripting (XSS) vulnerability in the shopping-cart screen in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2013-2312
|
2013-05-30 13:00 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260678
|
- |
|
lockon
|
ec-cube
|
data/class/pages/forgot/LC_Page_Forgot.php in LOCKON EC-CUBE 2.11.0 through 2.12.3enP2 does not properly validate the input to the password reminder function, which allows remote attackers to obtain …
|
CWE-20
Improper Input Validation
|
CVE-2013-2315
|
2013-05-30 13:00 |
2013-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260679
|
- |
|
gentoo
|
webmin
|
Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary Perl code via a crafted file associated with the type (aka monitor type name) parameter.
|
CWE-20
Improper Input Validation
|
CVE-2012-2981
|
2013-05-30 12:16 |
2012-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
260680
|
- |
|
gentoo
|
webmin
|
file/show.cgi in Webmin 1.590 and earlier allows remote authenticated users to execute arbitrary commands via an invalid character in a pathname, as demonstrated by a | (pipe) character.
|
NVD-CWE-Other
|
CVE-2012-2982
|
2013-05-30 12:16 |
2012-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|