5.8
    Medium

    CVE-2013-6127

    Last Modified: 5 Sept 2013

    The SUPERGRIDLib.SuperGrid ActiveX control in SuperGrid.ocx before 65.30.30000.10002 in WellinTech KingView before 6.53 does not properly restrict ReplaceDBFile method calls, which allows remote attackers to create or overwrite arbitrary files, and subsequently execute arbitrary programs, via the two pathname arguments, as demonstrated by a directory traversal attack.

    Source:blake
    Published:25 Oct 2013
    7.5
    High

    CVE-2013-6117

    Last Modified: 18 Nov 2013

    Dahua DVR 2.608.0000.0 and 2.608.GV00.0 allows remote attackers to bypass authentication and obtain sensitive information including user credentials, change user passwords, clear log files, and perform other actions via a request to TCP port 37777.

    Source:Jake Reynolds
    Published:11 Jul 2014
    5
    Medium

    CVE-2013-6114

    Last Modified: 8 Oct 2013

    Integer overflow in the OZDocument::parseElement function in Apple Motion 5.0.7 allows remote attackers to cause a denial of service (application crash) via a (1) large or (2) small value in the subview attribute of a viewer element in a .motn file.

    Source:Jean Pascal Pereira
    Published:4 Nov 2013
    7.2
    High

    CVE-2013-6079

    Last Modified: 19 Jun 2013

    Buffer overflow in MostGear Soft Easy LAN Folder Share 3.2.0.100 allows local users to cause a denial of service (application crash) and possibly execute arbitrary code via a long string in the (1) registration code field in the activate license window or the (2) HKLM\SOFTWARE\MostGear\EasyLanFolderShare_V1\License registry key. NOTE: it is not clear from the original report whether this issue crosses privilege boundaries. If not, then it should not be included in CVE.

    Source:ariarat
    Published:11 Oct 2013
    7.5
    High

    CVE-2013-6058

    Last Modified: 8 Nov 2013

    SQL injection vulnerability in appRain CMF 3.0.2 and earlier allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to blog-by-cat/.

    Source:High-Tech Bridge SA
    Published:14 Nov 2013
    5
    Medium

    CVE-2013-6043

    Last Modified: 28 Feb 2014

    The login function in Softaculous Webuzo before 2.1.4 provides different error messages for invalid authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of requests.

    Source:Mahendra
    Published:27 Dec 2014
    4.3
    Medium

    CVE-2013-6042

    Last Modified: 28 Feb 2014

    Cross-site scripting (XSS) vulnerability in filemanager/login.php in the File Manager module in Softaculous Webuzo before 2.1.4 allows remote attackers to inject arbitrary web script or HTML via the user parameter.

    Source:Mahendra
    Published:15 Nov 2013
    7.5
    High

    CVE-2013-6041

    Last Modified: 28 Feb 2014

    index.php in Softaculous Webuzo before 2.1.4 allows remote attackers to execute arbitrary commands via shell metacharacters in a SOFTCookies sid cookie within a login action.

    Source:Mahendra
    Published:27 Dec 2014
    8.1
    High

    CVE-2013-6040

    Last Modified: 25 Jan 2018

    MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls before version 4.0 vulnerable to arbitrary code via a crafted HTML document. Latest versions (4.0) of MW6 Aztec, DataMatrix, and MaxiCode ActiveX controls have resolved the issue

    Source:Pedro Ribeiro
    Published:21 Jan 2014
    8.5
    High

    CVE-2013-6027

    Last Modified: 25 Nov 2015

    Stack-based buffer overflow in the RuntimeDiagnosticPing function in /bin/webs on D-Link DIR-100 routers might allow remote authenticated administrators to execute arbitrary commands via a long set/runtime/diagnostic/pingIp parameter to Tools/tools_misc.xgi.

    Source:Craig Heffner
    Published:19 Oct 2013
    4
    Medium

    CVE-2013-6025

    Last Modified: 25 Nov 2015

    The XMLParse procedure in SAP Sybase Adaptive Server Enterprise (ASE) 15.7 ESD 2 allows remote authenticated users to read arbitrary files via a SQL statement containing an XML document with an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Source:Igor Bulatenko
    Published:19 Oct 2013
    7.8
    High

    CVE-2013-6023

    Last Modified: 14 Jul 2017

    Directory traversal vulnerability in the TVT TD-2308SS-B DVR with firmware 3.2.0.P-3520A-00 and earlier allows remote attackers to read arbitrary files via .. (dot dot) in the URI.

    Source:Cesar Neira
    Published:2 Nov 2013
    9.3
    Critical

    CVE-2013-6021

    Last Modified: 29 Oct 2013

    Buffer overflow in WGagent in WatchGuard WSM and Fireware before 11.8 allows remote attackers to execute arbitrary code via a long sessionid value in a cookie.

    Source:st3n
    Published:19 Oct 2013
    4.3
    Medium

    CVE-2013-6017

    Last Modified: 17 Dec 2015

    Cross-site scripting (XSS) vulnerability in Atmail Webmail Server before 7.2 allows remote attackers to inject arbitrary web script or HTML via the body of an e-mail message, as demonstrated by the SRC attribute of an IFRAME element.

    Source:Zhao Liang
    Published:12 Jan 2014
    5
    Medium

    CVE-2013-5979

    Last Modified: 18 Jul 2013

    Directory traversal vulnerability in Spring Signage Xibo 1.2.x before 1.2.3 and 1.4.x before 1.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the p parameter to index.php.

    Source:Mahendra
    Published:2 Oct 2013
    6.1
    Medium

    CVE-2013-5978

    Last Modified: 14 Oct 2013

    Multiple cross-site scripting (XSS) vulnerabilities in products.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) Product name or (2) Price description fields via a request to wp-admin/admin.php. NOTE: This issue may only cross privilege boundaries if used in combination with CVE-2013-5977.

    Source:absane
    Published:11 Dec 2019
    6.8
    Medium

    CVE-2013-5977

    Last Modified: 14 Oct 2013

    Cross-site request forgery (CSRF) vulnerability in Cart66Product.php in the Cart66 Lite plugin before 1.5.1.15 for WordPress allows remote attackers to hijack the authentication of administrators for requests that (1) create or modify products or conduct cross-site scripting (XSS) attacks via the (2) Product name or (3) Price description field in a product save action via a request to wp-admin/admin.php.

    Source:absane
    Published:1 Nov 2013
    7.5
    High

    CVE-2013-5967

    Last Modified: 21 Nov 2015

    Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.3 and earlier allow remote attackers to execute arbitrary SQL commands via the date_from parameter to (1) radar-iso27001-potential.php, (2) radar-iso27001-A12IS_acquisition-pot.php, (3) radar-iso27001-A11AccessControl-pot.php, (4) radar-iso27001-A10Com_OP_Mgnt-pot.php, or (5) radar-pci-potential.php in RadarReport/.

    Source:Yu-Chi Ding
    Published:9 Oct 2013
    5.1
    Medium

    CVE-2013-5962

    Last Modified: 18 Sept 2013

    Unrestricted file upload vulnerability in frames/upload-images.php in the Complete Gallery Manager plugin before 3.3.4 rev40279 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/[year]/[month]/.

    Source:Vulnerability-Lab
    Published:30 Sept 2013
    6.8
    Medium

    CVE-2013-5961

    Last Modified: 22 Sept 2013

    Unrestricted file upload vulnerability in lazyseo.php in the Lazy SEO plugin 1.1.9 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in lazy-seo/.

    Source:Ashiyane Digital Security Team
    Published:30 Sept 2013
    5.8
    Medium

    CVE-2013-5960

    Last Modified: 11 Apr 2025

    The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0.1 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against the intended cipher mode in a non-default configuration, a different vulnerability than CVE-2013-5679.

    Published:30 Sept 2013
    6.8
    Medium

    CVE-2013-5954

    Last Modified: 29 Dec 2015

    Multiple cross-site request forgery (CSRF) vulnerabilities in OpenX 2.8.11 and earlier allow remote attackers to hijack the authentication of administrators for requests that delete (1) users via admin/agency-user-unlink.php, (2) advertisers via admin/advertiser-delete.php, (3) banners via admin/banner-delete.php, (4) campaigns via admin/campaign-delete.php, (5) channels via admin/channel-delete.php, (6) affiliate websites via admin/affiliate-delete.php, or (7) zones via admin/zone-delete.php.

    Source:Mahmoud Ghorbanzadeh
    Published:25 Apr 2014
    8.5
    High

    CVE-2013-5948

    Last Modified: 7 Jun 2013

    The Network Analysis tab (Main_Analysis_Content.asp) in the ASUS RT-AC68U and other RT series routers with firmware before 3.0.0.4.374.5047 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the Target field (destIP parameter).

    Source:drone
    Published:21 Apr 2014
    9.8
    Critical

    CVE-2013-5945

    Last Modified: 4 Dec 2016

    Multiple SQL injection vulnerabilities in D-Link DSR-150 with firmware before 1.08B44; DSR-150N with firmware before 1.05B64; DSR-250 and DSR-250N with firmware before 1.08B44; and DSR-500, DSR-500N, DSR-1000, and DSR-1000N with firmware before 1.08B77 allow remote attackers to execute arbitrary SQL commands via the password to (1) the login.authenticate function in share/lua/5.1/teamf1lualib/login.lua or (2) captivePortal.lua.

    Source:0_o
    Published:11 Feb 2020
    7.5
    High

    CVE-2013-5917

    Last Modified: 23 Sept 2013

    SQL injection vulnerability in wp-comments-post.php in the NOSpam PTI plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the comment_post_ID parameter.

    Source:Alexandro Silva
    Published:23 Sept 2013
    10
    Critical

    CVE-2013-5912

    Last Modified: 2 Dec 2015

    VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in the fileName parameter during an importFile action.

    Source:Eduardo Gonzalez
    Published:28 Nov 2013
    5
    Medium

    CVE-2013-5880

    Last Modified: 17 Dec 2015

    Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 12.2.0, 12.2.1, and 12.2.2 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.

    Source:Oracle
    Published:15 Jan 2014
    5
    Medium

    CVE-2013-5877

    Last Modified: 10 Oct 2016

    Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.0, and 12.2.1 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.

    Source:Portcullis
    Published:15 Jan 2014
    10
    Critical

    CVE-2013-5842

    Last Modified: 11 Apr 2025

    Unspecified vulnerability in Oracle Java SE 7u40 and earlier, Java SE 6u60 and earlier, Java SE 5.0u51 and earlier, and Java SE Embedded 7u40 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Libraries, a different vulnerability than CVE-2013-5850.

    Published:15 Oct 2013
    5
    Medium

    CVE-2013-5795

    Last Modified: 10 Oct 2016

    Unspecified vulnerability in the Oracle Demantra Demand Management component in Oracle Supply Chain Products Suite 7.2.0.3 SQL-Server, 7.3.0, 7.3.1, 12.2.1, 12.2.2, and 12.2.3 allows remote attackers to affect confidentiality via unknown vectors related to DM Others.

    Source:Portcullis
    Published:15 Jan 2014
    1.5
    Low

    CVE-2013-5791

    Last Modified: 27 Jan 2014

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.4.0 and 8.4.1 allows context-dependent attackers to affect availability via unknown vectors related to Outside In Filters. NOTE: the previous information is from the October 2013 CPU. Oracle has not commented on claims from a third party that the issue is a stack-based buffer overflow in the Microsoft Access 1.x parser in vsacs.dll before 8.4.0.108 and before 8.4.1.52, which allows attackers to execute arbitrary code via a long field (aka column) name.

    Source:Citadelo
    Published:16 Oct 2013
    Low

    CVE-2013-5759

    Last Modified: 13 Jun 2014

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5758. Reason: This candidate is not an independent vulnerability; it is resultant from CVE-2013-5758. Notes: All CVE users should reference CVE-2013-5758 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Mr.Un1k0d3r
    Published:3 Aug 2014
    9
    Critical

    CVE-2013-5758

    Last Modified: 13 Jun 2014

    cgi-bin/cgiServer.exx in Yealink VoIP Phone SIP-T38G allows remote authenticated users to execute arbitrary commands by calling the system method in the body of a request, as demonstrated by running unauthorized services, changing directory permissions, and modifying files.

    Source:Mr.Un1k0d3r
    Published:3 Aug 2014
    4
    Medium

    CVE-2013-5757

    Last Modified: 19 Jul 2017

    Absolute path traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a full pathname in the dumpConfigFile function in the command parameter to cgi-bin/cgiServer.exx.

    Source:Mr.Un1k0d3r
    Published:3 Aug 2014
    4
    Medium

    CVE-2013-5756

    Last Modified: 19 Jul 2017

    Directory traversal vulnerability in Yealink VoIP Phone SIP-T38G allows remote authenticated users to read arbitrary files via a .. (dot dot) in the page parameter to cgi-bin/cgiServer.exx.

    Source:Mr.Un1k0d3r
    Published:3 Aug 2014
    10
    Critical

    CVE-2013-5755

    Last Modified: 13 Jun 2014

    config/.htpasswd in Yealink IP Phone SIP-T38G has a hardcoded password of (1) user (s7C9Cx.rLsWFA) for the user account, (2) admin (uoCbM.VEiKQto) for the admin account, and (3) var (jhl3iZAe./qXM) for the var account, which makes it easier for remote attackers to obtain access via unspecified vectors.

    Source:Mr.Un1k0d3r
    Published:16 Jul 2014
    6.8
    Medium

    CVE-2013-5748

    Last Modified: 30 Sept 2013

    Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote attackers to hijack the authentication of users for requests that add projects via an add_project action.

    Source:Ryan Dewhurst
    Published:12 May 2014
    7.1
    High

    CVE-2013-5745

    Last Modified: 17 Sept 2013

    The vino_server_client_data_pending function in vino-server.c in GNOME Vino 2.26.1, 2.32.1, 3.7.3, and earlier, and 3.8 when encryption is disabled, does not properly clear client data when an error causes the connection to close during authentication, which allows remote attackers to cause a denial of service (infinite loop, CPU and disk consumption) via multiple crafted requests during authentication.

    Source:Trustwave's SpiderLabs
    Published:21 Apr 2010
    9.8
    Critical

    CVE-2013-5743

    Last Modified: 15 Oct 2013

    Multiple SQL injection vulnerabilities in Zabbix 1.8.x before 1.8.18rc1, 2.0.x before 2.0.9rc1, and 2.1.x before 2.1.7.

    Source:Jason Kratzer
    Published:11 Dec 2019
    6.8
    Medium

    CVE-2013-5730

    Last Modified: 12 Sept 2013

    Multiple cross-site request forgery (CSRF) vulnerabilities in D-Link DSL-2740B Gateway with firmware EU_1.00 allow remote attackers to hijack the authentication of administrators for requests that (1) enable or disable Wireless MAC Address Filters via a wlFltMode action to wlmacflt.cmd, (2) enable or disable firewall protections via a request to scdmz.cmd, or (3) enable or disable remote management via a save action to scsrvcntr.cmd.

    Source:Ivano Binetti
    Published:19 Nov 2013
    4.3
    Medium

    CVE-2013-5716

    Last Modified: 10 Oct 2016

    Gretech GOM Media Player 2.2.53.5169 and possibly earlier allows remote attackers to cause a denial of service (application crash) via a crafted WAV file.

    Source:ariarat
    Published:9 Sept 2013
    7.2
    High

    CVE-2013-5701

    Last Modified: 19 Nov 2015

    Multiple untrusted search path vulnerabilities in (1) Watchguard Log Collector (wlcollector.exe) and (2) Watchguard WebBlocker Server (wbserver.exe) in WatchGuard Server Center 11.7.4, 11.7.3, and possibly earlier allow local users to gain privileges via a Trojan horse wgpr.dll file in the application's bin directory.

    Source:Julien Ahrens
    Published:3 Oct 2013
    7.5
    High

    CVE-2013-5697

    Last Modified: 30 Sept 2013

    SQL injection vulnerability in mod_accounting.c in the mod_accounting module 0.5 and earlier for Apache allows remote attackers to execute arbitrary SQL commands via a Host header.

    Source:Wireghoul
    Published:30 Sept 2013
    6.8
    Medium

    CVE-2013-5696

    Last Modified: 23 Sept 2013

    inc/central.class.php in GLPI before 0.84.2 does not attempt to make install/install.php unavailable after an installation is completed, which allows remote attackers to conduct cross-site request forgery (CSRF) attacks, and (1) perform a SQL injection via an Etape_4 action or (2) execute arbitrary PHP code via an update_1 action.

    Source:Metasploit
    Published:23 Sept 2013
    7.5
    High

    CVE-2013-5694

    Last Modified: 31 Oct 2013

    SQL injection vulnerability in status/service/acknowledge in Opsview before 4.4.1 allows remote attackers to execute arbitrary SQL commands via the service_selection parameter.

    Source:J. Oquendo
    Published:5 Nov 2013
    4.3
    Medium

    CVE-2013-5693

    Last Modified: 25 Sept 2013

    Cross-site scripting (XSS) vulnerability in X2Engine X2CRM before 3.5 allows remote attackers to inject arbitrary web script or HTML via the model parameter to index.php/admin/editor.

    Source:High-Tech Bridge SA
    Published:30 Sept 2013
    8.5
    High

    CVE-2013-5692

    Last Modified: 25 Sept 2013

    Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php/admin/translationManager.

    Source:High-Tech Bridge SA
    Published:30 Sept 2013
    Low

    CVE-2013-5689

    Last Modified: 10 Sept 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-5688. Reason: This issue has been MERGED with CVE-2013-5688 in accordance with CVE content decisions, because it is the same type of vulnerability affecting the same versions. Notes: All CVE users should reference CVE-2013-5688 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Trustwave's SpiderLabs
    Published:5 Nov 2013
    5.5
    Medium

    CVE-2013-5688

    Last Modified: 10 Sept 2013

    Multiple directory traversal vulnerabilities in index.php in AjaXplorer 5.0.2 and earlier allow remote authenticated users to read arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the file parameter in a (1) download or (2) get_content action, or (3) upload arbitrary files via a ../%00 (dot dot backslash encoded null byte) in the dir parameter in an upload action.

    Source:Trustwave's SpiderLabs
    Published:5 Nov 2013
    6.8
    Medium

    CVE-2013-5680

    Last Modified: 2 Oct 2013

    Heap-based buffer overflow in hfaxd in HylaFAX+ 5.2.4 through 5.5.3, when using LDAP authentication, might allow remote attackers to cause a denial of service (child hang) or execute arbitrary code via a long USER command.

    Source:Dennis Jenkins
    Published:6 Apr 2014