Unknown · CVSS Not scored
Directory traversal vulnerability in an unspecified signed Java applet in the client-side components in F5 BIG-IP APM 10.1.0 through 10.2.4 and 11.0.0 through 11.3.0, FirePass 6.0.0 through 6.1.0 and 7.0.0, and other products "when APM is provisioned," allows remote attackers to upload and execute arbitrary files via a .. (dot dot) in the filename parameter.
Published Aug 9, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The Kepware DNP Master Driver for the KEPServerEX Communications Platform before 5.12.140.0 allows remote attackers to cause a denial of service (master-station infinite loop) via crafted DNP3 packets to TCP port 20000 and allows physically proximate attackers to cause a denial of service (master-station infinite loop) via crafted input over a serial line.
Published Aug 22, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL commands via the "n" parameter to (1) browse_videos.php or (2) members.php. NOTE: the cat parameter is already covered by CVE-2008-4157.
Published Aug 19, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The Yahoo! Japan Yafuoku! application 4.3.0 and earlier for iOS and Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
Published Aug 21, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords via a getList action.
Published Aug 28, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
Published Aug 9, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Unspecified vulnerability in HP StoreOnce D2D Backup System 1.x before 1.2.19 and 2.x before 2.3.0 allows remote attackers to cause a denial of service via unknown vectors.
Published Aug 28, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Cross-site request forgery (CSRF) vulnerability in saveProperties.html in Corporater EPM Suite allows remote attackers to hijack the authentication of arbitrary users for requests that change passwords.
Published Aug 28, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Buffer overflow in the exposure correction code in LibRaw before 0.15.1 allows context-dependent attackers to cause a denial of service (crash) and possibly execute arbitrary code via unspecified vectors.
Published Aug 14, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Cross-site request forgery (CSRF) vulnerability in admin/setting.php in the Xhanch - My Twitter plugin before 2.7.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change unspecified settings.
Published Aug 9, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The automatic update request in Nagstamont before 0.9.10 uses a cleartext base64 format for transmission of a username and password, which allows remote attackers to obtain sensitive information by sniffing the network.
Published Aug 16, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The Python client in Apache Qpid before 2.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Published Aug 23, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
CRLF injection vulnerability in Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a MIME header.
Published Aug 23, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The C-Series Rack Server component 1.4 in Cisco Unified Computing System (UCS) does not properly restrict inbound access to ports, which allows remote attackers to cause a denial of service (Integrated Management Controller reboot or hang) via crafted packets, as demonstrated by nmap, aka Bug ID CSCtx19850.
Published Aug 1, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Puppet Enterprise before 3.0.1 includes version information for the Apache and Phusion Passenger products in its HTTP response headers, which allows remote attackers to obtain sensitive information.
Published Aug 20, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The Stage File Proxy module 7.x-1.x before 7.x-1.4 for Drupal allows remote attackers to cause a denial of service (file operations performance degradation and failure) via a large number of requests.
Published Aug 28, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Puppet Enterprise before 3.0.1 does not use a session timeout, which makes it easier for attackers to gain privileges by leveraging an unattended workstation.
Published Aug 20, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
SQL injection vulnerability in modules/rss/rss.php in Cotonti before 0.9.14 allows remote attackers to execute arbitrary SQL commands via the "c" parameter to index.php.
Published Aug 9, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
ZOLL Defibrillator / Monitor X Series has a default (1) supervisor password and (2) service password, which allows physically proximate attackers to modify device configuration and cause a denial of service (adverse human health effects).
Published Aug 12, 2014 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Multiple cross-site scripting (XSS) vulnerabilities in Alkacon OpenCms before 8.5.2 allow remote attackers to inject arbitrary web script or HTML via the (1) title parameter to system/workplace/views/admin/admin-main.jsp or the (2) requestedResource parameter to system/login/index.html.
Published Aug 9, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 3.8.3 through 3.8.16 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the filename of an attachment.
Published Aug 23, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Schneider Electric Trio J-Series License Free Ethernet Radio with firmware 3.6.0 through 3.6.3 uses the same AES encryption key across different customers' installations, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation.
Published Aug 28, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
SQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands via the search[gender] parameter to user/browse/view_/.
Published Aug 14, 2013 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The contact-form-plugin plugin before 3.3.5 for WordPress has XSS.
Published Aug 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The slidedeck2 plugin before 2.3.5 for WordPress has file inclusion.
Published Aug 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The simple-fields plugin before 1.2 for WordPress has CSRF in the admin interface.
Published Aug 14, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
gd_interpolation.c in the GD Graphics Library (aka libgd) before 2.1.1, as used in PHP before 5.5.36, 5.6.x before 5.6.22, and 7.x before 7.0.7, allows remote attackers to cause a denial of service (out-of-bounds read) or possibly have unspecified other impact via a crafted image that is mishandled by the imagescale function.
Published Aug 7, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The reflex-gallery plugin before 1.4.3 for WordPress has XSS.
Published Aug 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Windu CMS 2.2 allows XSS via the name parameter to admin/content/edit or admin/content/add, or the username parameter to admin/users.
Published Aug 1, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The events-manager plugin before 5.3.9 for WordPress has XSS in the search form field.
Published Aug 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Windu CMS 2.2 allows CSRF via admin/users/?mn=admin.message.error to add an admin account.
Published Aug 1, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The events-manager plugin before 5.5 for WordPress has XSS via EM_Ticket::get_post.
Published Aug 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Full path disclosure in the Googlemaps plugin before 3.1 for Joomla!.
Published Aug 29, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Integer underflow in regcomp.c in Perl before 5.20, as used in Apple OS X before 10.10.5 and other products, allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long digit string associated with an invalid backreference within a regular expression.
Published Aug 16, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The events-manager plugin before 5.3.6.1 for WordPress has XSS via the booking form and admin areas.
Published Aug 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The events-manager plugin before 5.5.2 for WordPress has XSS in the booking form.
Published Aug 22, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla! allows remote attackers to inject arbitrary web script or HTML via the xmlns parameter.
Published Aug 28, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Insecure Temporary file vulnerability in /tmp/kamailio_fifo in kamailio 4.0.1.
Published Aug 29, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to bypass an intended protection mechanism.
Published Aug 29, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cross-site scripting (XSS) vulnerability in the Googlemaps plugin before 3.1 for Joomla!.
Published Aug 29, 2017 · Updated Aug 6, 2024
Unknown · CVSS Not scored
linenoise, as used in Redis before 3.2.3, uses world-readable permissions for .rediscli_history, which allows local users to obtain sensitive information by reading the file.
Published Aug 10, 2016 · Updated Aug 6, 2024
Unknown · CVSS Not scored
GE Healthcare Centricity PACS Workstation 4.0 and 4.0.1 has a password of (1) CANal1 for the Administrator user and (2) iis for the IIS user, which has unspecified impact and attack vectors related to TimbuktuPro. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires it.
Published Aug 4, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The contact-form-plugin plugin before 3.52 for WordPress has XSS.
Published Aug 13, 2019 · Updated Aug 6, 2024
Unknown · CVSS Not scored
In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.
Published Aug 8, 2018 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The Ad Hoc Reporting feature in GE Healthcare Centricity DMS 4.2 has a password of Never!Mind for the Administrator user, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.
Published Aug 4, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
GE Healthcare Discovery NM 750b has a password of 2getin for the insite account for (1) Telnet and (2) FTP, which has unspecified impact and attack vectors. NOTE: it is not clear whether this password is default, hardcoded, or dependent on another system or product that requires a fixed value.
Published Aug 4, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Buffer overflow in the skip-scan optimization in SQLite 3.8.2 allows remote attackers to cause a denial of service (crash) via crafted SQL statements.
Published Aug 12, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The getaddrinfo function in glibc before 2.15, when compiled with libidn and the AI_IDN flag is used, allows context-dependent attackers to cause a denial of service (invalid free) and possibly execute arbitrary code via unspecified vectors, as demonstrated by an internationalized domain name to ping6.
Published Aug 26, 2015 · Updated Aug 6, 2024
Unknown · CVSS Not scored
The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string. NOTE: this issue was SPLIT from CVE-2013-6771 per ADT2 due to different vulnerability types.
Published Aug 7, 2014 · Updated Aug 6, 2024
Unknown · CVSS Not scored
Cobham SAILOR 900 VSAT; SAILOR FleetBroadBand 150, 250, and 500; EXPLORER BGAN; and AVIATOR 200, 300, 350, and 700D devices do not properly restrict password recovery, which allows attackers to obtain administrative privileges by leveraging physical access or terminal access to spoof a reset code.
Published Aug 15, 2014 · Updated Aug 6, 2024