CVE-2013-2000 to CVE-2013-2999
136 CVEs with public proof-of-concept exploits.
- CVE-2013-20061 PoCOpenStack Identity (Keystone) Grizzly 2013.1.1, when DEBUG mode logging is enabled, logs the (1) admin_token and (2) LDAP password in…
- CVE-2013-20091 PoCWordPress WP Super Cache Plugin 1.2 has Remote PHP Code Execution
- CVE-2013-20105 PoCsWordPress W3 Total Cache Plugin 0.9.2.8 has a Remote PHP Code Execution Vulnerability
- CVE-2013-202812 PoCsThe ngx_http_parse_chunked function in http/ngx_http_parse.c in nginx 1.3.9 through 1.4.0 allows remote attackers to cause a denial of…
- CVE-2013-20501 PoCSQL injection vulnerability in the miq_policy controller in Red Hat CloudForms 2.0 Management Engine (CFME) 5.1 and ManageIQ Enterprise…
- CVE-2013-20683 PoCsMultiple directory traversal vulnerabilities in the AgentController in Red Hat CloudForms Management Engine 2.0 allow remote attackers to…
- CVE-2013-20721 PoCBuffer overflow in the Python bindings for the xc_vcpu_setaffinity call in Xen 4.0.x, 4.1.x, and 4.2.x allows local administrators with…
- CVE-2013-20881 PoCcontrib/hook-scripts/svn-keyword-check.pl in Subversion before 1.6.23 allows remote authenticated users with commit permissions to execute…
- CVE-2013-209411 PoCsKEVThe perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows…
- CVE-2013-20951 PoCrubygem-openshift-origin-controller: API can be used to create applications via cartridge_cache.rb URI.prase() to perform command injection
- CVE-2013-20975 PoCsZPanel through 10.1.0 has Remote Command Execution
- CVE-2013-21071 PoCCross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack…
- CVE-2013-21081 PoCWordPress WP Cleanfix Plugin 2.4.4 has CSRF
- CVE-2013-21132 PoCsThe create method in app/controllers/users_controller.rb in Foreman before 1.2.0-RC2 allows remote authenticated users with permissions to…
- CVE-2013-21152 PoCsApache Struts 2 before 2.3.14.2 allows remote attackers to execute arbitrary OGNL code via a crafted request that is not properly handled…
- CVE-2013-21181 PoCSPIP 3.0.x before 3.0.9, 2.1.x before 2.1.22, and 2.0.x before 2.0.23 allows remote attackers to gain privileges and "take editorial…
- CVE-2013-21213 PoCsEval injection vulnerability in the create method in the Bookmarks controller in Foreman before 1.2.0-RC2 allows remote authenticated…
- CVE-2013-21311 PoCFormat string vulnerability in the rrdtool module 1.4.7 for Python, as used in Zenoss, allows context-dependent attackers to cause a…
- CVE-2013-21341 PoCApache Struts 2 before 2.3.14.3 allows remote attackers to execute arbitrary OGNL code via a request with a crafted action name that is…
- CVE-2013-21433 PoCsThe users controller in Katello 1.5.0-14 and earlier, and Red Hat Satellite, does not check authorization for the update_roles action,…
- CVE-2013-21461 PoCarch/x86/kernel/cpu/perf_event_intel.c in the Linux kernel before 3.8.9, when the Performance Events Subsystem is enabled, specifies an…
- CVE-2013-21601 PoCThe streaming XML parser in Apache CXF 2.5.x before 2.5.10, 2.6.x before 2.6.7, and 2.7.x before 2.7.4 allows remote attackers to cause a…
- CVE-2013-21653 PoCsResourceBuilderImpl.java in the RichFaces 3.x through 5.x implementation in Red Hat JBoss Web Framework Kit before 2.3.0, Red Hat JBoss…
- CVE-2013-21715 PoCsThe vm_map_lookup function in sys/vm/vm_map.c in the mmap implementation in the kernel in FreeBSD 9.0 through 9.1-RELEASE-p4 does not…
- CVE-2013-21731 PoCwp-includes/class-phpass.php in WordPress 3.5.1, when a password-protected post exists, allows remote attackers to cause a denial of…
- CVE-2013-21821 PoCThe Mandril security plugin in Monkey HTTP Daemon (monkeyd) before 1.5.0 allows remote attackers to bypass access restrictions via a…
- CVE-2013-21865 PoCsThe DiskFileItem class in Apache Commons FileUpload, as used in Red Hat JBoss BRMS 5.3.1; JBoss Portal 4.3 CP07, 5.2.2, and 6.0.0; and Red…
- CVE-2013-21991 PoCThe HTTP API in WordPress before 3.5.2 allows remote attackers to send HTTP requests to intranet servers via unspecified vectors, related…
- CVE-2013-22001 PoCWordPress before 3.5.2 does not properly check the capabilities of roles, which allows remote authenticated users to bypass intended…
- CVE-2013-22011 PoCMultiple cross-site scripting (XSS) vulnerabilities in WordPress before 3.5.2 allow remote attackers to inject arbitrary web script or…
- CVE-2013-22021 PoCWordPress before 3.5.2 allows remote attackers to read arbitrary files via an oEmbed XML provider response containing an external entity…
- CVE-2013-22031 PoCWordPress before 3.5.2, when the uploads directory forbids write access, allows remote attackers to obtain sensitive information via an…
- CVE-2013-22041 PoCmoxieplayer.as in Moxiecode moxieplayer, as used in the TinyMCE Media plugin in WordPress before 3.5.2 and other products, does not…
- CVE-2013-22051 PoCThe default configuration of SWFUpload in WordPress before 3.5.2 has an unrestrictive security.allowDomain setting, which allows remote…
- CVE-2013-22181 PoCDouble free vulnerability in the virConnectListAllInterfaces method in interface/interface_backend_netcf.c in libvirt 1.0.6 allows remote…
- CVE-2013-22252 PoCsinc/ticket.class.php in GLPI 0.83.9 and earlier allows remote attackers to unserialize arbitrary PHP objects via the _predefined_fields…
- CVE-2013-22261 PoCMultiple SQL injection vulnerabilities in GLPI before 0.83.9 allow remote attackers to execute arbitrary SQL commands via the (1)…
- CVE-2013-22272 PoCsGLPI 0.83.7 has Local File Inclusion in common.tabs.php.
- CVE-2013-22482 PoCsMultiple open redirect vulnerabilities in Apache Struts 2.0.0 through 2.3.15 allow remote attackers to redirect users to arbitrary web…
- CVE-2013-225110 PoCsKEVApache Struts 2.0.0 through 2.3.15 allows remote attackers to execute arbitrary OGNL expressions via a parameter with a crafted (1)…
- CVE-2013-22611 PoCCryptocat before 2.0.22 Chrome Extension 'img/keygen.gif' has Information Disclosure
- CVE-2013-22671 PoCPHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the…
- CVE-2013-22711 PoCThe D-Link DSL-2740B Gateway with firmware EU_1.0, when an active administrator session exists, allows remote attackers to bypass…
- CVE-2013-22872 PoCsMultiple cross-site scripting (XSS) vulnerabilities in views/notify.php in the Uploader plugin 1.0.4 for WordPress allow remote attackers…
- CVE-2013-22891 PoCCross-site scripting (XSS) vulnerability in admin/templates/default.php in Batavi 1.2.2 allows remote attackers to inject arbitrary web…
- CVE-2013-22944 PoCsMultiple cross-site scripting (XSS) vulnerabilities in ViewGit before 0.0.7 allow remote repository users to inject arbitrary web script…
- CVE-2013-22991 PoCCross-site scripting (XSS) vulnerability in Advantech WebAccess (formerly BroadWin WebAccess) before 7.1 2013.05.30 allows remote…
- CVE-2013-23332 PoCsUnspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via…
- CVE-2013-23432 PoCsUnspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute…
- CVE-2013-23474 PoCsThe Backup Client Service (OmniInet.exe) in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary commands or cause…
- CVE-2013-23672 PoCsMultiple unspecified vulnerabilities in HP SiteScope 11.20 and 11.21, when SOAP is used, allow remote attackers to execute arbitrary code…
- CVE-2013-23702 PoCsUnspecified vulnerability in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka…
- CVE-2013-24161 PoCUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier allows remote…
- CVE-2013-24191 PoCUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and…
- CVE-2013-24233 PoCsKEVUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, and OpenJDK 7, allows…
- CVE-2013-24602 PoCsUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, and OpenJDK 7, allows…
- CVE-2013-24653 PoCsKEVUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and…
- CVE-2013-24701 PoCUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and…
- CVE-2013-24721 PoCUnspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 21 and earlier, 6 Update 45 and…
- CVE-2013-24742 PoCsDirectory traversal vulnerability in AWS XMS 2.5 allows remote attackers to view arbitrary files via the 'what' parameter.
- CVE-2013-24923 PoCsStack-based buffer overflow in Firebird 2.1.3 through 2.1.5 before 18514, and 2.5.1 through 2.5.3 before 26623, on Windows allows remote…
- CVE-2013-24981 PoCSQL injection vulnerability in the login page in flexycms/modules/user/user_manager.php in SimpleHRM 2.3, 2.2, and earlier allows remote…
- CVE-2013-25011 PoCCross-site scripting (XSS) vulnerability in the Terillion Reviews plugin before 1.2 for WordPress allows remote attackers to inject…
- CVE-2013-25031 PoCPrivoxy before 3.0.21 does not properly handle Proxy-Authenticate and Proxy-Authorization headers in the client-server data stream, which…
- CVE-2013-25041 PoCCross-site scripting (XSS) vulnerability in SPS/Portal/default.aspx in Service Desk in Matrix42 Service Store 5.3 SP3 (aka 5.33.946.0)…
- CVE-2013-25121 PoCThe ftpd gem 0.2.1 for Ruby allows remote attackers to execute arbitrary OS commands via shell metacharacters in a LIST or NLST command…
- CVE-2013-25161 PoCVulnerability in FileUtils v0.7, Ruby Gem Fileutils <= v0.7 Command Injection vulnerability in user supplied url variable that is passed…
- CVE-2013-25512 PoCsKEVUse-after-free vulnerability in Microsoft Internet Explorer 6 through 10 allows remote attackers to execute arbitrary code via a crafted…
- CVE-2013-25591 PoCSQL injection vulnerability in Symphony CMS before 2.3.2 allows remote authenticated users to execute arbitrary SQL commands via the sort…
- CVE-2013-25601 PoCDirectory traversal vulnerability in the web interface on Foscam devices with firmware before 11.37.2.49 allows remote attackers to read…
- CVE-2013-25673 PoCsAn Authentication Bypass vulnerability exists in the web interface in Zavio IP Cameras through 1.6.03 due to a hardcoded admin account…
- CVE-2013-25682 PoCsA Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 via the ap parameter to /cgi-bin/mft/wireless_mft.cgi, which…
- CVE-2013-25692 PoCsA Security Bypass vulnerability exists in Zavio IP Cameras through 1.6.3 because the RTSP protocol authentication is disabled by default,…
- CVE-2013-25702 PoCsA Command Injection vulnerability exists in Zavio IP Cameras through 1.6.3 in the General.Time.NTP.Server parameter to the sub_C8C8…
- CVE-2013-25713 PoCsIris 3.8 before build 1548, as used in Xpient point of sale (POS) systems, allows remote attackers to execute arbitrary commands via a…
- CVE-2013-25723 PoCsA Security Bypass vulnerability exists in TP-LINK IP Cameras TL-SC 3130, TL-SC 3130G, 3171G, 4171G, and 3130 1.6.18P12 due to default…
- CVE-2013-25732 PoCsA Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130,…
- CVE-2013-25743 PoCsAn Access vulnerability exists in FOSCAM IP Camera FI8620 due to insufficient access restrictions in the /tmpfs/ and /log/ directories,…
- CVE-2013-25762 PoCsBuffer overflow in Artweaver before 3.1.6 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code…
- CVE-2013-25772 PoCsBuffer overflow in XnView before 2.04 allows remote attackers to execute arbitrary code via a crafted PCT file.
- CVE-2013-25782 PoCscgi-bin/admin/servetest in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware…
- CVE-2013-25791 PoCTP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an…
- CVE-2013-25801 PoCUnrestricted file upload vulnerability in cgi-bin/uploadfile in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and…
- CVE-2013-25811 PoCcgi-bin/firmwareupgrade in TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware…
- CVE-2013-25862 PoCsXAMPP 1.8.1 does not properly restrict access to xampp/lang.php, which allows remote attackers to modify xampp/lang.tmp and execute…
- CVE-2013-25942 PoCsSQL injection vulnerability in reports/calldiary.php in Hornbill Supportworks ITSM 1.0.0 through 3.4.14 allows remote attackers to execute…
- CVE-2013-25951 PoCThe device-initialization functionality in the MSM camera driver for the Linux kernel 2.6.x and 3.x, as used in Qualcomm Innovation Center…
- CVE-2013-25962 PoCsKEVInteger overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of…
- CVE-2013-25971 PoCKEVStack-based buffer overflow in the acdb_ioctl function in audio_acdb.c in the acdb audio driver for the Linux kernel 2.6.x and 3.x, as…
- CVE-2013-26182 PoCsCross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inject arbitrary web…
- CVE-2013-26192 PoCsDirectory traversal vulnerability in Aspen before 0.22 allows remote attackers to read arbitrary files via a .. (dot dot) to the default…
- CVE-2013-26212 PoCsOpen Redirection Vulnerability in the redir.php script in Telaen before 1.3.1 allows remote attackers to redirect victims to arbitrary…
- CVE-2013-26221 PoCCross-site Scripting (XSS) in UebiMiau 2.7.11 and earlier allows remote attackers to inject arbitrary web script or HTML via the…
- CVE-2013-26231 PoCCross-site Scripting (XSS) in Telaen before 1.3.1 allows remote attackers to inject arbitrary web script or HTML via the "f_email"…
- CVE-2013-26241 PoCTelean before 1.3.1 contains a full path disclosure vulnerability which could allow remote attackers to obtain sensitive information…
- CVE-2013-26271 PoCSQL injection vulnerability in action.php in Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to execute arbitrary…
- CVE-2013-26311 PoCTinyWebGallery (TWG) 1.8.9 and earlier contains a full path disclosure vulnerability which allows remote attackers to obtain sensitive…
- CVE-2013-26372 PoCsA Cross-Site Scripting (XSS) Vulnerability exists in OTRS ITSM prior to 3.2.4, 3.1.8, and 3.0.7 and FAQ prior to 2.1.4 and 2.0.8 via…
- CVE-2013-26392 PoCsCross-site scripting (XSS) vulnerability in CTERA Cloud Storage OS before 3.2.29.0, 3.2.42.0, and earlier allows remote attackers to…
- CVE-2013-26412 PoCsDirectory traversal vulnerability in patience.cgi in Sophos Web Appliance before 3.7.8.2 allows remote attackers to read arbitrary files…
- CVE-2013-26421 PoCSophos Web Appliance before 3.7.8.2 allows (1) remote attackers to execute arbitrary commands via shell metacharacters in the client-ip…
- CVE-2013-26431 PoCMultiple cross-site scripting (XSS) vulnerabilities in Sophos Web Appliance before 3.7.8.2 allow remote attackers to inject arbitrary web…
- CVE-2013-26451 PoCMultiple cross-site request forgery (CSRF) vulnerabilities on the TP-LINK WR1043N router with firmware TL-WR1043ND_V1_120405 allow remote…
- CVE-2013-26531 PoCsecurity/MemberLoginForm.php in SilverStripe 3.0.3 supports login using a GET request, which makes it easier for remote attackers to…
- CVE-2013-26721 PoCBrother MFC-9970CDW devices with firmware 0D allow cleartext submission of passwords.
- CVE-2013-26731 PoCBrother MFC-9970CDW 1.10 firmware L devices contain a security bypass vulnerability which allows physically proximate attackers to gain…
- CVE-2013-26741 PoCBrother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view…
- CVE-2013-26751 PoCBrother MFC-9970CDW 1.10 devices with Firmware L contain a Frameable response (Clickjacking) vulnerability which could allow remote…
- CVE-2013-26761 PoCBrother MFC-9970CDW 1.10 firmware L devices contain an information disclosure vulnerability which allows remote attackers to view private…
- CVE-2013-26785 PoCsCisco Linksys E4200 1.0.05 Build 7 routers contain a Local File Include Vulnerability which could allow remote attackers to obtain…
- CVE-2013-26795 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Cisco Linksys E4200 router with firmware 1.0.05 build 7 allow remote attackers to…
- CVE-2013-26802 PoCsCisco Linksys E4200 1.0.05 Build 7 devices store passwords in cleartext allowing remote attackers to obtain sensitive information.
- CVE-2013-26812 PoCsCisco Linksys E4200 1.0.05 Build 7 devices contain a Security Bypass Vulnerability which could allow remote attackers to gain unauthorized…
- CVE-2013-26822 PoCsCisco Linksys E4200 1.0.05 Build 7 devices contain a Clickjacking Vulnerability which allows remote attackers to obtain sensitive…
- CVE-2013-26832 PoCsCisco Linksys E4200 1.0.05 Build 7 devices contain an Information Disclosure Vulnerability which allows remote attackers to obtain private…
- CVE-2013-26842 PoCsCross-site Scripting (XSS) in Cisco Linksys E4200 1.0.05 Build 7 devices allows remote attackers to inject arbitrary web script or HTML…
- CVE-2013-26902 PoCsSQL injection vulnerability in index.php in Synchroweb Technology SynConnect 2.0 allows remote attackers to execute arbitrary SQL commands…
- CVE-2013-27122 PoCsCross-site scripting (XSS) vulnerability in services/get_article.php in KrisonAV CMS before 3.0.2 allows remote attackers to inject…
- CVE-2013-27132 PoCsCross-site request forgery (CSRF) vulnerability in users_maint.html in KrisonAV CMS before 3.0.2 allows remote attackers to hijack the…
- CVE-2013-27141 PoCCross-site Scripting (XSS) in WordPress podPress Plugin 8.8.10.13 could allow remote attackers to inject arbitrary web script or html via…
- CVE-2013-27294 PoCsKEVInteger overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute…
- CVE-2013-27303 PoCsBuffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute…
- CVE-2013-27391 PoCMiniDLNA has heap-based buffer overflow
- CVE-2013-27482 PoCsBelkin Wemo Switch before WeMo_US_2.00.2176.PVT could allow remote attackers to upload arbitrary files onto the system.
- CVE-2013-27501 PoCCross-site scripting (XSS) vulnerability in e107_plugins/content/handlers/content_preset.php in e107 before 1.0.3 allows remote attackers…
- CVE-2013-27513 PoCsEval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator before 4.1.12 and…
- CVE-2013-27542 PoCsCross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hijack the…
- CVE-2013-27602 PoCsBuffer overflow in Groovy Media Player 3.2.0 allows remote attackers to execute arbitrary code via a long string in a .m3u file.
- CVE-2013-27651 PoCThe ModSecurity module before 2.7.4 for the Apache HTTP Server allows remote attackers to cause a denial of service (NULL pointer…
- CVE-2013-27841 PoCTriangle Research International (aka Tri) Nano-10 PLC devices with firmware before r81 use an incorrect algorithm for bounds checking of…
- CVE-2013-28171 PoCAn ActiveX control in IcoLaunch.dll in Mitsubishi Electric Automation MC-WorX Suite 8.02 allows user-assisted remote attackers to execute…
- CVE-2013-28272 PoCsAn unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows…
- CVE-2013-28422 PoCsUse-after-free vulnerability in Google Chrome before 27.0.1453.93 allows remote attackers to cause a denial of service or possibly have…
- CVE-2013-28521 PoCFormat string vulnerability in the b43_request_firmware function in drivers/net/wireless/b43/main.c in the Broadcom B43 wireless driver in…
- CVE-2013-29451 PoCSQL injection vulnerability in blogs/admin.php in b2evolution before 4.1.7 allows remote authenticated administrators to execute arbitrary…
- CVE-2013-29772 PoCsInteger overflow in IBM Notes 8.5.x before 8.5.3 FP4 Interim Fix 1 and 9.x before 9.0 Interim Fix 1 on Windows, and 8.5.x before 8.5.3 FP5…