CVE-2013-5000 to CVE-2013-5999
97 CVEs with public proof-of-concept exploits.
- CVE-2013-50061 PoCmain_internet.php on the Western Digital My Net N600 and N750 with firmware 1.03.12 and 1.04.16, and the N900 and N900C with firmware…
- CVE-2013-50145 PoCsThe management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and…
- CVE-2013-50155 PoCsSQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1…
- CVE-2013-50199 PoCsStack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resource name in an HTTP…
- CVE-2013-50201 PoCMultiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in MiniBB before 3.0.1 allow remote attackers to inject arbitrary web…
- CVE-2013-50271 PoCCollabtive 1.0 has incorrect access control
- CVE-2013-50281 PoCSQL injection vulnerability in IT/hardware-list.dll in Kwoksys Kwok Information Server before 2.8.5 allows remote authenticated users to…
- CVE-2013-50301 PoCRuckus Wireless Zoneflex 2942 devices with firmware 9.6.0.0.267 allow remote attackers to bypass authentication, and subsequently access…
- CVE-2013-50363 PoCsThe Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the…
- CVE-2013-50371 PoCThe HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers to obtain the WPA…
- CVE-2013-50381 PoCThe HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had…
- CVE-2013-50391 PoCCross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote…
- CVE-2013-50453 PoCsMicrosoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain…
- CVE-2013-50581 PoCInteger overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows…
- CVE-2013-50655 PoCsKEVNDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted…
- CVE-2013-50912 PoCsSQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute…
- CVE-2013-50921 PoCCross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject…
- CVE-2013-50933 PoCsThe renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely,…
- CVE-2013-50941 PoCCross-site scripting (XSS) vulnerability in index.exp in McAfee Vulnerability Manager 7.5 allows remote attackers to inject arbitrary web…
- CVE-2013-50992 PoCsCross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote attackers to inject…
- CVE-2013-51121 PoCEvernote before 5.5.1 has insecure PIN storage
- CVE-2013-51132 PoCsLastPass prior to 2.5.1 has an insecure PIN implementation.
- CVE-2013-51142 PoCsLastPass prior to 2.5.1 allows secure wipe bypass.
- CVE-2013-51172 PoCsSQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote…
- CVE-2013-51181 PoCCross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attackers to inject…
- CVE-2013-51202 PoCsSQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2013-51212 PoCsSQL injection vulnerability in PHPFox before 3.6.0 (build6) allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2013-51231 PoCThe mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows…
- CVE-2013-51471 PoCPasscode Lock in Apple iOS before 7 does not properly manage the lock state, which allows physically proximate attackers to bypass an…
- CVE-2013-52115 PoCsThe monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic…
- CVE-2013-52181 PoCCross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web…
- CVE-2013-52191 PoCDirectory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a ..…
- CVE-2013-52201 PoCgoform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted…
- CVE-2013-52234 PoCsKEVMultiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject…
- CVE-2013-53091 PoCCross-site scripting (XSS) vulnerability in install/forum_data/src/custom_fields.inc.t in FUDforum 3.0.4.1 and earlier, when registering a…
- CVE-2013-53112 PoCsMultiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL commands via the "n"…
- CVE-2013-53122 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbitrary web script or…
- CVE-2013-53141 PoCCross-site scripting (XSS) vulnerability in serendipity_admin_image_selector.php in Serendipity 1.6.2 and earlier allows remote attackers…
- CVE-2013-53162 PoCsCross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators…
- CVE-2013-53172 PoCsCross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the…
- CVE-2013-53182 PoCsSQL injection vulnerability in Ginkgo CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the rang parameter to index.php.
- CVE-2013-53212 PoCsMultiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to…
- CVE-2013-53312 PoCsAdobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux,…
- CVE-2013-54473 PoCsStack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary…
- CVE-2013-54671 PoCMonitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server…
- CVE-2013-54863 PoCsDirectory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before…
- CVE-2013-55283 PoCsDirectory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote…
- CVE-2013-55721 PoCZabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the…
- CVE-2013-55732 PoCsCross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web…
- CVE-2013-55764 PoCsadministrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows…
- CVE-2013-55782 PoCsBuffer overflow in the ToDot method in the WINGRAPHVIZLib.NEATO ActiveX control in WinGraphviz.dll in StarUML allows remote attackers to…
- CVE-2013-55821 PoCAmmyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers…
- CVE-2013-56392 PoCsDirectory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrary files via a ..…
- CVE-2013-56403 PoCsMultiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) answer_id or…
- CVE-2013-56562 PoCsFuzeZip 1.0.0.131625 has a Local Buffer Overflow vulnerability
- CVE-2013-56571 PoCAultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request
- CVE-2013-56581 PoCAultWare pwStore 2010.8.30.0 has XSS
- CVE-2013-56601 PoCBuffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file.
- CVE-2013-56722 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in the IndiaNIC Testimonial plugin 2.2 for WordPress allow remote attackers to…
- CVE-2013-56732 PoCsSQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute…
- CVE-2013-56761 PoCThe Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords)…
- CVE-2013-56802 PoCsHeap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause…
- CVE-2013-56881 PoCMultiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read…
- CVE-2013-56922 PoCsDirectory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary…
- CVE-2013-56932 PoCsCross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2013-56942 PoCsSQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arbitrary SQL…
- CVE-2013-56963 PoCsinc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed,…
- CVE-2013-56971 PoCSQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute…
- CVE-2013-57011 PoCMultiple untrusted search path vulnerabilities in (1) Watchguard Log Collector (wlcollector.exe) and (2) Watchguard WebBlocker Server…
- CVE-2013-57162 PoCsGretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a…
- CVE-2013-57301 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in D-Link DSL-2740B Gateway with firmware EU_1.00 allow remote attackers to…
- CVE-2013-57381 PoCThe get_allowed_mime_types function in wp-includes/functions.php in WordPress before 3.6.1 does not require the unfiltered_html capability…
- CVE-2013-57391 PoCThe default configuration of WordPress before 3.6.1 does not prevent uploads of .swf and .exe files, which might make it easier for remote…
- CVE-2013-57432 PoCsMultiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.
- CVE-2013-57451 PoCThe vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is…
- CVE-2013-57481 PoCCross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote…
- CVE-2013-57552 PoCsconfig/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin…
- CVE-2013-57562 PoCsDirectory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a .. (dot…
- CVE-2013-57572 PoCsAbsolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full…
- CVE-2013-57584 PoCscgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system…
- CVE-2013-57912 PoCsUnspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.4.1 allows…
- CVE-2013-57951 PoCUnspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server,…
- CVE-2013-58421 PoCUnspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded…
- CVE-2013-58771 PoCUnspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server,…
- CVE-2013-58801 PoCUnspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and…
- CVE-2013-59121 PoCVhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code…
- CVE-2013-59171 PoCSQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers to execute…
- CVE-2013-59452 PoCsMultiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and…
- CVE-2013-59461 PoCThe runShellCmd function in systemCheck.htm in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250…
- CVE-2013-59481 PoCThe Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before…
- CVE-2013-59541 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication…
- CVE-2013-59612 PoCsUnrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute…
- CVE-2013-59622 PoCsUnrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for…
- CVE-2013-59672 PoCsMultiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote…
- CVE-2013-59772 PoCsCross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote…
- CVE-2013-59783 PoCsMultiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote…
- CVE-2013-59792 PoCsDirectory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read…