7.5
    High

    CVE-2013-7193

    Last Modified: 6 Dec 2015

    Multiple SQL injection vulnerabilities in C2C Forward Auction Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) pa parameter to auction/asp/list.asp, or the (2) UserID or (3) Password to auction/casp/admin.asp.

    Source:R3d-D3V!L
    Published:21 Dec 2013
    7.5
    High

    CVE-2013-7192

    Last Modified: 7 Dec 2015

    Multiple SQL injection vulnerabilities in Dynamic Biz Website Builder (QuickWeb) allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to apps/news-events/newdetail.asp, or the (2) UserID or (3) Password to login.asp.

    Source:R3d-D3V!L
    Published:21 Dec 2013
    5
    Medium

    CVE-2013-7190

    Last Modified: 24 Oct 2016

    Multiple directory traversal vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to read arbitrary files via the (1) tmpid parameter to websitebuilder/showtemplateimage.php, (2) fname parameter to admin/downloadfile.php, or (3) id parameter to support/admin/csvdownload.php; or (4) have an unspecified impact via unspecified vectors in support/parser/main_smtp.php.

    Source:i-Hmx
    Published:20 Dec 2013
    7.5
    High

    CVE-2013-7189

    Last Modified: 5 Feb 2017

    Multiple SQL injection vulnerabilities in iScripts AutoHoster, possibly 2.4, allow remote attackers to execute arbitrary SQL commands via the cmbdomain parameter to (1) checktransferstatus.php, (2) checktransferstatusbck.php, or (3) additionalsettings.php; or (4) invno parameter to payinvoiceothers.php.

    Source:i-Hmx
    Published:20 Dec 2013
    7.5
    High

    CVE-2013-7187

    Last Modified: 10 Dec 2013

    SQL injection vulnerability in form.php in the FormCraft plugin 1.3.7 and earlier for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Ashiyane Digital Security Team
    Published:20 Dec 2013
    9.3
    Critical

    CVE-2013-7186

    Last Modified: 4 Sept 2016

    Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long string in a .m3u file.

    Source:metacom
    Published:20 Dec 2013
    7.8
    High

    CVE-2013-7185

    Last Modified: 23 Dec 2013

    PotPlayer 1.5.40688: .avi File Memory Corruption

    Source:ariarat
    Published:14 Jan 2020
    4.3
    Medium

    CVE-2013-7184

    Last Modified: 20 Dec 2013

    Gretech GOM Media Player 2.2.56.5158 and earlier allows remote attackers to cause a denial of service (memory corruption) via a crafted AVI file.

    Source:ariarat
    Published:24 Jan 2014
    7.8
    High

    CVE-2013-7183

    Last Modified: 21 Dec 2015

    cgi-bin/reboot.cgi on Seowon Intech SWC-9100 routers allows remote attackers to (1) cause a denial of service (reboot) via a default_reboot action or (2) reset all configuration values via a factory_default action.

    Source:Josue Rojas
    Published:4 Feb 2014
    8.3
    High

    CVE-2013-7179

    Last Modified: 21 Dec 2015

    The ping functionality in cgi-bin/diagnostic.cgi on Seowon Intech SWC-9100 routers allows remote attackers to execute arbitrary commands via shell metacharacters in the ping_ipaddr parameter.

    Source:Josue Rojas
    Published:4 Feb 2014
    7.5
    High

    CVE-2013-7139

    Last Modified: 14 Jan 2014

    SQL injection vulnerability in download.php in Horizon Quick Content Management System (QCMS) 4.0 and earlier allows remote to execute arbitrary SQL commands via the category parameter.

    Source:High-Tech Bridge SA
    Published:9 Jan 2014
    9.8
    Critical

    CVE-2013-7137

    Last Modified: 14 Jan 2014

    The "remember me" functionality in login.php in Burden before 1.8.1 allows remote attackers to bypass authentication and gain privileges by setting the burden_user_rememberme cookie to 1.

    Source:High-Tech Bridge SA
    Published:26 Jan 2014
    9.3
    Critical

    CVE-2013-7136

    Last Modified: 15 Nov 2017

    The UPC Ireland Cisco EPC 2425 router (aka Horizon Box) does not have a sufficiently large number of possible WPA-PSK passphrases, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Source:Matt O'Connor
    Published:19 Dec 2013
    5.5
    Medium

    CVE-2013-7108

    Last Modified: 6 Dec 2015

    Multiple off-by-one errors in Nagios Core 3.5.1, 4.0.2, and earlier, and Icinga before 1.8.5, 1.9 before 1.9.4, and 1.10 before 1.10.2 allow remote authenticated users to obtain sensitive information from process memory or cause a denial of service (crash) via a long string in the last key value in the variable list to the process_cgivars function in (1) avail.c, (2) cmd.c, (3) config.c, (4) extinfo.c, (5) histogram.c, (6) notifications.c, (7) outages.c, (8) status.c, (9) statusmap.c, (10) summary.c, and (11) trends.c in cgi/, which triggers a heap-based buffer over-read.

    Source:DTAG Group Information Security
    Published:20 Dec 2013
    5
    Medium

    CVE-2013-7097

    Last Modified: 6 Dec 2015

    Directory traversal vulnerability in 7 Media Web Solutions eduTrac before 1.1.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the showmask parameter to installer/overview.php.

    Source:High-Tech Bridge
    Published:8 Jan 2014
    5
    Medium

    CVE-2013-7091

    Last Modified: 14 Jul 2017

    Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.

    Source:rubina119
    Published:13 Dec 2013
    6.8
    Medium

    CVE-2013-7057

    Last Modified: 27 Oct 2014

    Cross-site request forgery (CSRF) vulnerability in Axway SecureTransport 5.1 SP2 and earlier allows remote attackers to hijack the authentication of unspecified users for requests that upload arbitrary files via a crafted request to api/v1.0/files/.

    Source:Emmanuel Law
    Published:4 Nov 2014
    9.8
    Critical

    CVE-2013-7055

    Last Modified: 5 Feb 2014

    D-Link DIR-100 4.03B07 has PPTP and poe information disclosure

    Source:Felix Richter
    Published:4 Feb 2020
    6.1
    Medium

    CVE-2013-7054

    Last Modified: 5 Feb 2014

    D-Link DIR-100 4.03B07: cli.cgi XSS

    Source:Felix Richter
    Published:4 Feb 2020
    8.8
    High

    CVE-2013-7053

    Last Modified: 5 Feb 2014

    D-Link DIR-100 4.03B07: cli.cgi CSRF

    Source:Felix Richter
    Published:4 Feb 2020
    9.8
    Critical

    CVE-2013-7052

    Last Modified: 5 Feb 2014

    D-Link DIR-100 4.03B07: security bypass via an error in the cliget.cgi script

    Source:Felix Richter
    Published:4 Feb 2020
    8.8
    High

    CVE-2013-7051

    Last Modified: 5 Feb 2014

    D-Link DIR-100 4.03B07: cli.cgi security bypass due to failure to check authentication parameters

    Source:Felix Richter
    Published:4 Feb 2020
    8.3
    High

    CVE-2013-7043

    Last Modified: 2 Dec 2013

    Multiple cross-site request forgery (CSRF) vulnerabilities on Cisco Scientific Atlanta DPR2320R2 routers with software 2.0.2r1262-090417 allow remote attackers to hijack the authentication of administrators for requests that (1) change a password via the Password parameter to goform/RgSecurity; (2) reboot the device via the Restart parameter to goform/restart; (3) modify Wi-Fi settings, as demonstrated by the WpaPreSharedKey parameter to goform/wlanSecurity; or (4) modify parental controls via the ParentalPassword parameter to goform/RgParentalBasic.

    Source:sajith
    Published:10 Dec 2013
    7.3
    High

    CVE-2013-7030

    Last Modified: 18 Dec 2013

    The TFTP service in Cisco Unified Communications Manager (aka CUCM or Unified CM) allows remote attackers to obtain sensitive information from a phone via an RRQ operation, as demonstrated by discovering a cleartext UseUserCredential field in an SPDefault.cnf.xml file. NOTE: the vendor reportedly disputes the significance of this report, stating that this is an expected default behavior, and that the product's documentation describes use of the TFTP Encrypted Config option in addressing this issue

    Source:daniel svartman
    Published:12 Dec 2013
    3.5
    Low

    CVE-2013-7025

    Last Modified: 5 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in ematStaticAlertTypes.jsp in the Alert Settings section in Dell SonicWALL Global Management System (GMS), Analyzer, and UMA EM5000 7.1 SP1 before Hotfix 134235 allow remote authenticated users to inject arbitrary web script or HTML via the (1) valfield_1 or (2) value_1 parameter to createNewThreshold.jsp.

    Source:Vulnerability-Lab
    Published:9 Dec 2013
    7.5
    High

    CVE-2013-6987

    Last Modified: 24 Dec 2013

    Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remote attackers to read, write, and delete arbitrary files via a .. (dot dot) in the (1) path parameter to file_delete.cgi or (2) folder_path parameter to file_share.cgi in webapi/FileStation/; (3) dlink parameter to fbdownload/; or unspecified parameters to (4) html5_upload.cgi, (5) file_download.cgi, (6) file_sharing.cgi, (7) file_MVCP.cgi, or (8) file_rename.cgi in webapi/FileStation/.

    Source:Andrea Fabrizi
    Published:31 Dec 2013
    7.5
    High

    CVE-2013-6985

    Last Modified: 4 Dec 2015

    SQL injection vulnerability in m_worklog/log_searchday.jsp in Enorth Webpublisher CMS, possibly 5.0 and earlier, allows remote attackers to execute arbitrary SQL commands via the thisday parameter.

    Source:xin.wang
    Published:9 Dec 2013
    6.8
    Medium

    CVE-2013-6976

    Last Modified: 16 Dec 2013

    Cross-site request forgery (CSRF) vulnerability in goform/Quick_setup on Cisco EPC3925 devices allows remote attackers to hijack the authentication of administrators for requests that change a password via the Password and PasswordReEnter parameters, aka Bug ID CSCuh37496.

    Source:Jeroen - IT Nerdbox
    Published:19 Dec 2013
    10
    Critical

    CVE-2013-6955

    Last Modified: 24 Dec 2013

    webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to arbitrary files, and consequently execute arbitrary code, via a pathname in the SLICEUPLOAD X-TMP-FILE HTTP header.

    Source:Metasploit
    Published:9 Jan 2014
    6.8
    Medium

    CVE-2013-6937

    Last Modified: 14 Nov 2013

    Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the name attribute of the cols element in a .wstyle file.

    Source:Mike Czumak
    Published:4 Dec 2013
    7.5
    High

    CVE-2013-6936

    Last Modified: 12 Jul 2015

    Multiple SQL injection vulnerabilities in ajaxfs.php in the Ajax forum stat (Ajaxfs) Plugin 2.0 for MyBB (aka MyBulletinBoard) allow remote attackers to execute arbitrary SQL commands via the (1) tooltip or (2) usertooltip parameter.

    Source:IeDb ir
    Published:4 Dec 2013
    9.3
    Critical

    CVE-2013-6935

    Last Modified: 12 Nov 2013

    Buffer overflow in VideoCharge Software Watermark Master 2.2.23 allows remote attackers to execute arbitrary code via a long string in the SourcePath value in a .wcf file.

    Source:metacom
    Published:4 Dec 2013
    9.8
    Critical

    CVE-2013-6924

    Last Modified: 27 Oct 2016

    Seagate BlackArmor NAS devices with firmware sg2000-2000.1331 allow remote attackers to execute arbitrary commands via shell metacharacters in the ip parameter to backupmgt/getAlias.php.

    Source:Jeroen - IT Nerdbox
    Published:11 Oct 2017
    4.3
    Medium

    CVE-2013-6923

    Last Modified: 6 Jan 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to inject arbitrary web script or HTML via the (1) fullname parameter to admin/access_control_user_edit.php or (2) workname parameter to admin/network_workgroup_domain.php.

    Source:Jeroen - IT Nerdbox
    Published:9 Jan 2014
    6.8
    Medium

    CVE-2013-6922

    Last Modified: 6 Jan 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Seagate BlackArmor NAS 220 devices with firmware sg2000-2000.1331 allow remote attackers to hijack the authentication of administrators for requests that (1) add user accounts via a crafted request to admin/access_control_user_add.php; (2) modify or (3) delete user accounts; (4) perform a factory reset; (5) perform a device reboot; or (6) add, (7) modify, or (8) delete shares and volumes.

    Source:Jeroen - IT Nerdbox
    Published:21 Jan 2014
    5
    Medium

    CVE-2013-6890

    Last Modified: 8 Dec 2015

    denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login names.

    Source:Helmut Grohne
    Published:23 Dec 2013
    10
    Critical

    CVE-2013-6884

    Last Modified: 17 Dec 2013

    The write-blocker in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a has a default "ditto" username and password, which allows remote attackers to gain privileges.

    Source:Martin Wundram
    Published:7 Jan 2014
    6.8
    Medium

    CVE-2013-6883

    Last Modified: 17 Dec 2013

    Cross-site request forgery (CSRF) vulnerability in CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to hijack the authentication of administrators for requests that modify the disk erase technique settings via unspecified vectors.

    Source:Martin Wundram
    Published:17 Dec 2013
    4.3
    Medium

    CVE-2013-6882

    Last Modified: 17 Dec 2013

    Multiple cross-site scripting (XSS) vulnerabilities in CRU Ditto Forensic FieldStation with firmware 2013Oct15a and earlier allow (1) remote attackers to inject arbitrary web script or HTML via the username parameter in a login or (2) remote authenticated users to inject arbitrary web script or HTML via unspecified form fields.

    Source:Martin Wundram
    Published:17 Dec 2013
    10
    Critical

    CVE-2013-6881

    Last Modified: 17 Dec 2013

    CRU Ditto Forensic FieldStation with firmware before 2013Oct15a allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) sector size or (2) skip count fields for the forensic imaging task.

    Source:Martin Wundram
    Published:7 Jan 2014
    9.3
    Critical

    CVE-2013-6877

    Last Modified: 28 Dec 2013

    Heap-based buffer overflow in RealNetworks RealPlayer before 17.0.4.61 on Windows, and Mac RealPlayer before 12.0.1.1738, allows remote attackers to execute arbitrary code via a long string in the TRACKID element of an RMP file, a different vulnerability than CVE-2013-7260.

    Source:Gabor Seljan
    Published:19 Dec 2013
    7.5
    High

    CVE-2013-6875

    Last Modified: 30 Nov 2015

    SQL injection vulnerability in functions/prepend_adm.php in Nagios Core Config Manager in Nagios XI before 2012R2.4 allows remote attackers to execute arbitrary SQL commands via the tfPassword parameter to nagiosql/index.php.

    Source:Denis Andzakovic
    Published:26 Nov 2013
    9.3
    Critical

    CVE-2013-6874

    Last Modified: 22 Nov 2013

    Stack-based buffer overflow in Vortex Light Alloy before 4.7.4 allows remote attackers to execute arbitrary code via a long URL in a .m3u file.

    Source:Mike Czumak
    Published:26 Nov 2013
    7.5
    High

    CVE-2013-6873

    Last Modified: 2 Dec 2015

    SQL injection vulnerability in Testa Online Test Management System (OTMS) 2.0.0.2 allows remote attackers to execute arbitrary SQL commands via the test_id parameter.

    Source:Ashiyane Digital Security Team
    Published:26 Nov 2013
    6.5
    Medium

    CVE-2013-6872

    Last Modified: 2 Jan 2017

    SQL injection vulnerability in managetimetracker.php in Collabtive before 1.2 allows remote authenticated users to execute arbitrary SQL commands via the id parameter in a projectpdf action.

    Source:Yogesh Phadtare
    Published:21 Jan 2014
    6.8
    Medium

    CVE-2013-6852

    Last Modified: 31 Oct 2016

    Cross-site request forgery (CSRF) vulnerability in html/json.html on HP 2620 switches allows remote attackers to hijack the authentication of administrators for requests that change an administrative password via the setPassword method.

    Source:Hubert Gradek
    Published:22 Nov 2013
    7.5
    High

    CVE-2013-6839

    Last Modified: 17 Dec 2013

    SQL injection vulnerability in InstantSoft InstantCMS 1.10.3 and earlier allows remote attackers to execute arbitrary SQL commands via the orderby parameter to catalog/[id].

    Source:High-Tech Bridge SA
    Published:13 Dec 2013
    5
    Medium

    CVE-2013-6835

    Last Modified: 28 Dec 2015

    TelephonyUI Framework in Apple iOS 7 before 7.1, when Safari is used, does not require user confirmation for FaceTime audio calls, which allows remote attackers to obtain telephone number or e-mail address information via a facetime-audio: URL.

    Source:Guillaume Ross
    Published:14 Mar 2014
    7.2
    High

    CVE-2013-6831

    Last Modified: 6 Dec 2013

    PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms has a sudoers file that does not properly restrict user specifications, which allows local users to gain privileges via a sudo command that leverages access to the qmailq account.

    Source:Ruben Garrote García
    Published:20 Nov 2013
    7.5
    High

    CVE-2013-6830

    Last Modified: 6 Dec 2013

    admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitrary commands via shell metacharacters in the nsserver parameter during an nslookup operation.

    Source:Ruben Garrote García
    Published:20 Nov 2013