CVE-2013-7000 to CVE-2013-7999
76 CVEs with public proof-of-concept exploits.
- CVE-2013-70041 PoCD-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and…
- CVE-2013-70051 PoCD-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and…
- CVE-2013-70091 PoCThe rpza_decode_stream function in libavcodec/rpza.c in FFmpeg before 2.1 does not properly maintain a pointer to pixel data, which allows…
- CVE-2013-70131 PoCThe g2m_init_buffers function in libavcodec/g2meet.c in FFmpeg before 2.1 uses an incorrect ordering of arithmetic operations, which…
- CVE-2013-70253 PoCsMultiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell SonicWALL Global…
- CVE-2013-70302 PoCsThe TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information…
- CVE-2013-70432 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417…
- CVE-2013-70513 PoCsD-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters
- CVE-2013-70522 PoCsD-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script
- CVE-2013-70532 PoCsD-Link DIR-100 4.03B07: cli.cgi CSRF
- CVE-2013-70542 PoCsD-Link DIR-100 4.03B07: cli.cgi XSS
- CVE-2013-70552 PoCsD-Link DIR-100 4.03B07 has PPTP and poe information disclosure
- CVE-2013-70572 PoCsCross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to hijack the…
- CVE-2013-70701 PoCThe handle_request function in lib/HTTPServer.pm in Monitorix before 3.3.1 allows remote attackers to execute arbitrary commands via shell…
- CVE-2013-70711 PoCCross-site scripting (XSS) vulnerability in the handle_request function in lib/HTTPServer.pm in Monitorix before 3.4.0 allows remote…
- CVE-2013-70917 PoCsDirectory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and…
- CVE-2013-70971 PoCDirectory traversal vulnerability in 7 Media Web Solutions eduTrac before 1.1.2 allows remote attackers to read arbitrary files via a ..…
- CVE-2013-71021 PoCMultiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3)…
- CVE-2013-71081 PoCMultiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2…
- CVE-2013-71362 PoCsThe UPC Ireland Cisco EPC 2425 router (aka Horizon Box) does not have a sufficiently large number of possible WPA-PSK passphrases, which…
- CVE-2013-71372 PoCsThe "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges…
- CVE-2013-71391 PoCSQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote to execute…
- CVE-2013-71791 PoCThe ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute arbitrary commands…
- CVE-2013-71831 PoCcgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) via a…
- CVE-2013-71842 PoCsGretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption) via a crafted…
- CVE-2013-71852 PoCsPotPlayer 1.5.40688: .avi File Memory Corruption
- CVE-2013-71862 PoCsBuffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long string in a .m3u…
- CVE-2013-71872 PoCsSQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute…
- CVE-2013-71895 PoCsMultiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via…
- CVE-2013-71905 PoCsMultiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the…
- CVE-2013-71922 PoCsMultiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbitrary SQL commands…
- CVE-2013-71932 PoCsMultiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the…
- CVE-2013-71942 PoCsMultiple cross-site scripting (XSS) vulnerabilities in www/administrator.php in eFront 3.6.14 (build 18012) allow remote authenticated…
- CVE-2013-71961 PoCstatic/ajax.php in PHPFox 3.7.3, 3.7.4, and 3.7.5 allows remote authenticated users to bypass intended "Only Me" restrictions and comment…
- CVE-2013-72042 PoCsCross-site request forgery (CSRF) vulnerability in set_users.cgi in Conceptronic CIPCAMPTIWL Camera 1.0 with firmware 21.37.2.49 allows…
- CVE-2013-72091 PoCCross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attackers to hijack the…
- CVE-2013-72191 PoCSQL injection vulnerability in vote.php in the 2Glux Sexy Polling (com_sexypolling) component before 1.0.9 for Joomla! allows remote…
- CVE-2013-72332 PoCsCross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and…
- CVE-2013-72403 PoCsDirectory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read…
- CVE-2013-72462 PoCsBuffer overflow in the IconCreate method in an ActiveX control in the DaumGame ActiveX plugin 1.1.0.4 and 1.1.0.5 allows remote attackers…
- CVE-2013-72471 PoCcgi-bin/tsaws.cgi in Franklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 allows remote attackers…
- CVE-2013-72481 PoCFranklin Fueling Systems TS-550 evo with firmware 2.0.0.6833 and other versions before 2.4.0 has a hardcoded password for the roleDiag…
- CVE-2013-72591 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in Neo4J 1.9.2 allow remote attackers to hijack the authentication of…
- CVE-2013-72603 PoCsMultiple stack-based buffer overflows in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allow…
- CVE-2013-72742 PoCsCross-site scripting (XSS) vulnerability in Wallpaper Script 3.5.0082 allows remote authenticated users to inject arbitrary web script or…
- CVE-2013-72781 PoCSQL injection vulnerability in Naxtech CMS Afroditi 1.0 allows remote attackers to execute arbitrary SQL commands via the id parameter to…
- CVE-2013-72804 PoCsBuffer overflow in HansoTools Hanso Player 2.1.0, 2.5.0, and earlier allows remote attackers to cause a denial of service (crash) via a…
- CVE-2013-72821 PoCThe management web interface on the Nisuta NS-WIR150NE router with firmware 5.07.41 and Nisuta NS-WIR300N router with firmware…
- CVE-2013-72855 PoCsXstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to…
- CVE-2013-72871 PoCMobileIron VSP < 5.9.1 and Sentry < 5.0 has an insecure encryption scheme.
- CVE-2013-73162 PoCsCross-site scripting (XSS) vulnerability in GitLab 6.0 and other versions before 6.5.0 allows remote attackers to inject arbitrary web…
- CVE-2013-73192 PoCsCross-site scripting (XSS) vulnerability in the Download Manager plugin before 2.5.9 for WordPress allows remote attackers to inject…
- CVE-2013-73311 PoCKEVThe Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to determine the existence of local…
- CVE-2013-73321 PoCThe Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier does not properly detect recursion during entity expansion,…
- CVE-2013-73461 PoCCross-site request forgery (CSRF) vulnerability in Symphony CMS before 2.3.2 allows remote attackers to hijack the authentication of…
- CVE-2013-73493 PoCsMultiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) news_id…
- CVE-2013-73511 PoCMultiple cross-site scripting (XSS) vulnerabilities in index.php in Shaarli allow remote attackers to inject arbitrary web script or HTML…
- CVE-2013-73681 PoCMultiple cross-site scripting (XSS) vulnerabilities in Gnew 2013.1 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2013-73751 PoCSQL injection vulnerability in includes/classes/Authenticate.class.php in PHP-Fusion 7.02.01 through 7.02.05 allows remote attackers to…
- CVE-2013-73761 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.10, possibly before revision 82710, allow remote attackers to…
- CVE-2013-73791 PoCThe admin API in the tomato module before 0.0.6 for Node.js does not properly check the access key when it is set to a string, which…
- CVE-2013-73822 PoCsVICIDIAL dialer (aka Asterisk GUI client) 2.8-403a, 2.7, 2.7RC1, and earlier has a hardcoded password of donotedit for the (1) VDAD and…
- CVE-2013-73872 PoCsSession fixation vulnerability in DataLife Engine (DLE) 9.7 and earlier allows remote attackers to hijack web sessions via the PHPSESSID…
- CVE-2013-73892 PoCsMultiple cross-site scripting (XSS) vulnerabilities in D-Link DIR-645 Router (Rev. A1) with firmware before 1.04B11 allow remote attackers…
- CVE-2013-73904 PoCsUnrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows…
- CVE-2013-73922 PoCsGitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/.
- CVE-2013-740911 PoCsBuffer overflow in ALLPlayer 5.6.2 through 5.8.1 allows remote attackers to cause a denial of service (crash) and possibly execute…
- CVE-2013-74171 PoCCross-site scripting (XSS) vulnerability in cgi-bin/ipinfo.cgi in IPCop (aka IPCop Firewall) before 2.1.3 allows remote attackers to…
- CVE-2013-74181 PoCcgi-bin/iptablesgui.cgi in IPCop (aka IPCop Firewall) before 2.1.5 allows remote authenticated users to execute arbitrary code via shell…
- CVE-2013-74201 PoCBuffer overflow in Hancom Office 2010 SE allows remote attackers to execute arbitrary via a long string in the Text attribute in a TEXTART…
- CVE-2013-74541 PoCThe validator module before 1.1.0 for Node.js allows remote attackers to bypass the cross-site scripting (XSS) filter via nested forbidden…
- CVE-2013-74661 PoCSimple Machines Forum (SMF) 2.0.4 allows local file inclusion, with resultant remote code execution, in install.php via ../ directory…
- CVE-2013-74671 PoCSimple Machines Forum (SMF) 2.0.4 allows XSS via the index.php?action=pm;sa=settings;save sa parameter.
- CVE-2013-74681 PoCSimple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.
- CVE-2013-74711 PoCAn issue was discovered in soap.cgi?service=WANIPConn1 on D-Link DIR-845 before v1.02b03, DIR-600 before v2.17b01, DIR-645 before…
- CVE-2013-74871 PoCOn Swann DVR04B, DVR08B, DVR-16CIF, and DVR16B devices, raysharpdvr application has a vulnerable call to “system”, which allows remote…