2.6
    Low

    CVE-2013-5679

    Last Modified: 11 Apr 2025

    The authenticated-encryption feature in the symmetric-encryption implementation in the OWASP Enterprise Security API (ESAPI) for Java 2.x before 2.1.0 does not properly resist tampering with serialized ciphertext, which makes it easier for remote attackers to bypass intended cryptographic protection mechanisms via an attack against authenticity in the default configuration, involving a null MAC and a zero MAC length.

    Published:30 Sept 2013
    4
    Medium

    CVE-2013-5676

    Last Modified: 21 Dec 2013

    The Jenkins Plugin for SonarQube 3.7 and earlier allows remote authenticated users to obtain sensitive information (cleartext passwords) by reading the value in the sonar.sonarPassword parameter from jenkins/configure.

    Source:Christian Catalano
    Published:6 Dec 2013
    7.5
    High

    CVE-2013-5673

    Last Modified: 3 Sept 2013

    SQL injection vulnerability in testimonial.php in the IndiaNIC Testimonial plugin 2.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the custom_query parameter in a testimonial_add action to wp-admin/admin-ajax.php.

    Source:RogueCoder
    Published:10 Sept 2013
    6.8
    Medium

    CVE-2013-5672

    Last Modified: 3 Sept 2013

    Multiple cross-site request forgery (CSRF) vulnerabilities in the IndiaNIC Testimonial plugin 2.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) add a testimonial via an iNIC_testimonial_save action; (2) add a listing template via an iNIC_testimonial_save_listing_template action; (3) add a widget template via an iNIC_testimonial_save_widget action; insert cross-site scripting (XSS) sequences via the (4) project_name, (5) project_url, (6) client_name, (7) client_city, (8) client_state, (9) description, (10) tags, (11) video_url, or (12) is_featured, (13) title, (14) widget_title, (15) no_of_testimonials, (16) filter_by_country, (17) filter_by_tags, or (18) widget_template parameter to wp-admin/admin-ajax.php.

    Source:RogueCoder
    Published:10 Sept 2013
    4.3
    Medium

    CVE-2013-5664

    Last Modified: 11 Apr 2025

    Cross-site scripting (XSS) vulnerability in the web-based device-management API browser in Palo Alto Networks PAN-OS before 4.1.13 and 5.0.x before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via crafted data, aka Ref ID 50908.

    Published:31 Aug 2013
    9.3
    Critical

    CVE-2013-5660

    Last Modified: 2 May 2013

    Buffer overflow in Power Software WinArchiver 3.2 allows remote attackers to execute arbitrary code via a crafted .zip file.

    Source:RealPentesting
    Published:25 Apr 2014
    7.5
    High

    CVE-2013-5657

    Last Modified: 18 Nov 2015

    AultWare pwStore 2010.8.30.0 has DoS via an empty HTTP request

    Source:Josep Pi Rodriguez
    Published:7 Jan 2020
    7.8
    High

    CVE-2013-5656

    Last Modified: 2 May 2013

    FuzeZip 1.0.0.131625 has a Local Buffer Overflow vulnerability

    Source:RealPentesting
    Published:7 Jan 2020
    7.5
    High

    CVE-2013-5640

    Last Modified: 12 Aug 2013

    Multiple SQL injection vulnerabilities in Gnew 2013.1 allow remote attackers to execute arbitrary SQL commands via the (1) answer_id or (2) question_id parameter to polls/vote.php, (3) story_id parameter to comments/add.php or (4) comments/edit.php, or (5) thread_id parameter to posts/add.php. NOTE: this issue was SPLIT due to differences in researchers and disclosure dates. CVE-2013-7349 already covers the news_id parameter to news/send.php, user_email parameter to users/register.php, and thread_id to posts/edit.php vectors.

    Source:LiquidWorm
    Published:1 Apr 2014
    7.5
    High

    CVE-2013-5639

    Last Modified: 2 Oct 2013

    Directory traversal vulnerability in users/login.php in Gnew 2013.1 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the gnew_language cookie.

    Source:High-Tech Bridge SA
    Published:11 Mar 2014
    Low

    CVE-2013-5633

    Last Modified: 27 Oct 2016

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A public posting on 20130831 referenced this ID for a specific issue, but that issue had not been assigned this ID by any CNA. Notes: The posting will later have IDs assigned in accordance with CVE content decisions

    Source:Kyle Lovett
    Published:17 Sept 2013
    Low

    CVE-2013-5632

    Last Modified: 27 Oct 2016

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A public posting on 20130831 referenced this ID for a specific issue, but that issue had not been assigned this ID by any CNA. Notes: The posting will later have IDs assigned in accordance with CVE content decisions

    Source:Kyle Lovett
    Published:17 Sept 2013
    Low

    CVE-2013-5631

    Last Modified: 27 Oct 2016

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A public posting on 20130831 referenced this ID for a specific issue, but that issue had not been assigned this ID by any CNA. Notes: The posting will later have IDs assigned in accordance with CVE content decisions

    Source:Kyle Lovett
    Published:17 Sept 2013
    Low

    CVE-2013-5630

    Last Modified: 3 Sept 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A public posting on 20130831 referenced this ID for a specific issue, but that issue had not been assigned this ID by any CNA. Notes: The posting will later have IDs assigned in accordance with CVE content decisions

    Source:Kyle Lovett
    Published:17 Sept 2013
    Low

    CVE-2013-5628

    Last Modified: 27 Oct 2016

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A public posting on 20130831 referenced this ID for a specific issue, but that issue had not been assigned this ID by any CNA. Notes: The posting will later have IDs assigned in accordance with CVE content decisions

    Source:Kyle Lovett
    Published:17 Sept 2013
    Low

    CVE-2013-5627

    Last Modified: 3 Sept 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A public posting on 20130831 referenced this ID for a specific issue, but that issue had not been assigned this ID by any CNA. Notes: The posting will later have IDs assigned in accordance with CVE content decisions

    Source:Kyle Lovett
    Published:17 Sept 2013
    Low

    CVE-2013-5625

    Last Modified: 3 Sept 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A public posting on 20130831 referenced this ID for a specific issue, but that issue had not been assigned this ID by any CNA. Notes: The posting will later have IDs assigned in accordance with CVE content decisions

    Source:Kyle Lovett
    Published:17 Sept 2013
    Low

    CVE-2013-5624

    Last Modified: 3 Sept 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A public posting on 20130831 referenced this ID for a specific issue, but that issue had not been assigned this ID by any CNA. Notes: The posting will later have IDs assigned in accordance with CVE content decisions

    Source:Kyle Lovett
    Published:17 Sept 2013
    Low

    CVE-2013-5623

    Last Modified: 27 Oct 2016

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A public posting on 20130831 referenced this ID for a specific issue, but that issue had not been assigned this ID by any CNA. Notes: The posting will later have IDs assigned in accordance with CVE content decisions

    Source:Kyle Lovett
    Published:17 Sept 2013
    Low

    CVE-2013-5622

    Last Modified: 3 Sept 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A public posting on 20130831 referenced this ID for a specific issue, but that issue had not been assigned this ID by any CNA. Notes: The posting will later have IDs assigned in accordance with CVE content decisions

    Source:Kyle Lovett
    Published:17 Sept 2013
    Low

    CVE-2013-5621

    Last Modified: 3 Sept 2013

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A public posting on 20130831 referenced this ID for a specific issue, but that issue had not been assigned this ID by any CNA. Notes: The posting will later have IDs assigned in accordance with CVE content decisions

    Source:Kyle Lovett
    Published:17 Sept 2013
    Low

    CVE-2013-5620

    Last Modified: 18 Dec 2016

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: A public posting on 20130831 referenced this ID for a specific issue, but that issue had not been assigned this ID by any CNA. Notes: The posting will later have IDs assigned in accordance with CVE content decisions

    Source:Kyle Lovett
    Published:17 Sept 2013
    7.8
    High

    CVE-2013-5582

    Last Modified: 24 Jan 2014

    Ammyy Admin 3.2 and earlier stores the client ID at a fixed memory location, which might make it easier for user-assisted remote attackers to bypass authentication by running a local program that extracts a field from the AA_v3.2.exe file.

    Source:Bhadresh Patel
    Published:11 Feb 2020
    Low

    CVE-2013-5581

    Last Modified: 24 Jan 2014

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Source:Bhadresh Patel
    Published:19 Feb 2020
    9.3
    Critical

    CVE-2013-5578

    Last Modified: 3 Aug 2013

    Buffer overflow in the ToDot method in the WINGRAPHVIZLib.NEATO ActiveX control in WinGraphviz.dll in StarUML allows remote attackers to execute arbitrary code via a long argument.

    Source:d3b4g
    Published:25 Aug 2013
    6.8
    Medium

    CVE-2013-5576

    Last Modified: 19 Dec 2016

    administrator/components/com_media/helpers/media.php in the media manager in Joomla! 2.5.x before 2.5.14 and 3.x before 3.1.5 allows remote authenticated users or remote attackers to bypass intended access restrictions and upload files with dangerous extensions via a filename with a trailing . (dot), as exploited in the wild in August 2013.

    Source:Metasploit
    Published:9 Oct 2013
    Low

    CVE-2013-5575

    Last Modified: 7 Mar 2019

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Source:x90c
    Published:26 Sept 2013
    4.3
    Medium

    CVE-2013-5573

    Last Modified: 21 Dec 2013

    Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web script or HTML via the Description field in the user configuration.

    Source:Christian Catalano
    Published:16 Dec 2013
    3.5
    Low

    CVE-2013-5572

    Last Modified: 23 Feb 2015

    Zabbix 2.0.5 allows remote authenticated users to discover the LDAP bind password by leveraging management-console access and reading the ldap_bind_password value in the HTML source code.

    Source:Pablo González
    Published:1 Oct 2013
    4
    Medium

    CVE-2013-5528

    Last Modified: 7 Dec 2016

    Directory traversal vulnerability in the Tomcat administrative web interface in Cisco Unified Communications Manager allows remote authenticated users to read arbitrary files via directory traversal sequences in an unspecified input string, aka Bug ID CSCui78815.

    Source:justpentest
    Published:11 Oct 2013
    10
    Critical

    CVE-2013-5486

    Last Modified: 3 Dec 2013

    Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to write arbitrary files via the chartid parameter, aka Bug IDs CSCue77035 and CSCue77036. NOTE: this can be leveraged to execute arbitrary commands by using the JBoss autodeploy functionality.

    Source:Metasploit
    Published:23 Sept 2013
    7.2
    High

    CVE-2013-5467

    Last Modified: 29 Oct 2014

    Monitoring Agent for UNIX Logs 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP09, and 6.2.3 through FP04 and Monitoring Server (ms) and Shared Libraries (ax) 6.2.0 through FP03, 6.2.1 through FP04, 6.2.2 through FP08, 6.2.3 through FP01, and 6.3.0 through FP01 in IBM Tivoli Monitoring (ITM) on UNIX allow local users to gain privileges via unspecified vectors.

    Source:Robert Jaroszuk
    Published:29 Aug 2014
    6.8
    Medium

    CVE-2013-5447

    Last Modified: 7 Jan 2014

    Stack-based buffer overflow in IBM Forms Viewer 4.x before 4.0.0.3 and 8.x before 8.0.1.1 allows remote attackers to execute arbitrary code via an XFDL form with a long fontname value.

    Source:Metasploit
    Published:10 Dec 2013
    9.3
    Critical

    CVE-2013-5331

    Last Modified: 29 Apr 2014

    Adobe Flash Player before 11.7.700.257 and 11.8.x and 11.9.x before 11.9.900.170 on Windows and Mac OS X and before 11.2.202.332 on Linux, Adobe AIR before 3.9.0.1380, Adobe AIR SDK before 3.9.0.1380, and Adobe AIR SDK & Compiler before 3.9.0.1380 allow remote attackers to execute arbitrary code via crafted .swf content that leverages an unspecified "type confusion," as exploited in the wild in December 2013.

    Source:Metasploit
    Published:10 Dec 2013
    7.5
    High

    CVE-2013-5321

    Last Modified: 18 Dec 2016

    Multiple SQL injection vulnerabilities in AlienVault Open Source Security Information Management (OSSIM) 4.1 allow remote attackers to execute arbitrary SQL commands via the (1) sensor parameter in a Query action to forensics/base_qry_main.php; the (2) tcp_flags[] or (3) tcp_port[0][4] parameter to forensics/base_stat_alerts.php; the (4) ip_addr[1][8] or (5) port_type parameter to forensics/base_stat_ports.php; or the (6) sortby or (7) rvalue parameter in a search action to vulnmeter/index.php.

    Source:Glafkos Charalambous
    Published:20 Aug 2013
    7.5
    High

    CVE-2013-5318

    Last Modified: 10 Aug 2013

    SQL injection vulnerability in Ginkgo CMS 5.0 allows remote attackers to execute arbitrary SQL commands via the rang parameter to index.php.

    Source:Raw-x
    Published:20 Aug 2013
    3.5
    Low

    CVE-2013-5317

    Last Modified: 3 Aug 2013

    Cross-site scripting (XSS) vulnerability in RiteCMS 1.0.0 allows remote authenticated users to inject arbitrary web script or HTML via the mode parameter to cms/index.php.

    Source:Yashar shahinzadeh
    Published:20 Aug 2013
    6.8
    Medium

    CVE-2013-5316

    Last Modified: 3 Aug 2013

    Cross-site request forgery (CSRF) vulnerability in RiteCMS 1.0.0 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via an edit user action to cms/index.php.

    Source:Yashar shahinzadeh
    Published:20 Aug 2013
    4.3
    Medium

    CVE-2013-5314

    Last Modified: 31 Oct 2016

    Cross-site scripting (XSS) vulnerability in serendipity_admin_image_selector.php in Serendipity 1.6.2 and earlier allows remote attackers to inject arbitrary web script or HTML via the serendipity[htmltarget] parameter.

    Source:Omar Kurt
    Published:19 Aug 2013
    4.3
    Medium

    CVE-2013-5312

    Last Modified: 21 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) n parameter to browse_videos.php or the (2) cat parameter to groups.php.

    Source:3spi0n
    Published:19 Aug 2013
    7.5
    High

    CVE-2013-5311

    Last Modified: 21 Dec 2016

    Multiple SQL injection vulnerabilities in Vastal I-Tech phpVID 1.2.3 allow remote attackers to execute arbitrary SQL commands via the "n" parameter to (1) browse_videos.php or (2) members.php. NOTE: the cat parameter is already covered by CVE-2008-4157.

    Source:3spi0n
    Published:19 Aug 2013
    5.4
    Medium

    CVE-2013-5223

    Last Modified: 11 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in D-Link DSL-2760U Gateway (Rev. E1) allow remote authenticated users to inject arbitrary web script or HTML via the (1) ntpServer1 parameter to sntpcfg.cgi, username parameter to (2) ddnsmngr.cmd or (3) todmngr.tod, (4) TodUrlAdd parameter to urlfilter.cmd, (5) appName parameter to scprttrg.cmd, (6) fltName in an add action or (7) rmLst parameter in a remove action to scoutflt.cmd, (8) groupName parameter to portmapcfg.cmd, (9) snmpRoCommunity parameter to snmpconfig.cgi, (10) fltName parameter to scinflt.cmd, (11) PolicyName in an add action or (12) rmLst parameter in a remove action to prmngr.cmd, (13) ippName parameter to ippcfg.cmd, (14) smbNetBiosName or (15) smbDirName parameter to samba.cgi, or (16) wlSsid parameter to wlcfg.wl.

    Source:XLabs Security
    Published:15 Nov 2013
    6.1
    Medium

    CVE-2013-5220

    Last Modified: 8 Nov 2013

    goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST data.

    Source:Oz Elisyan
    Published:30 Dec 2013
    3.3
    Low

    CVE-2013-5219

    Last Modified: 8 Nov 2013

    Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a request for /etc/passwd.

    Source:Oz Elisyan
    Published:30 Dec 2013
    2.9
    Low

    CVE-2013-5218

    Last Modified: 8 Nov 2013

    Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP table in wlanAccess.asp.

    Source:Oz Elisyan
    Published:30 Dec 2013
    5
    Medium

    CVE-2013-5211

    Last Modified: 28 Apr 2014

    The monlist feature in ntp_request.c in ntpd in NTP before 4.2.7p26 allows remote attackers to cause a denial of service (traffic amplification) via forged (1) REQ_MON_GETLIST or (2) REQ_MON_GETLIST_1 requests, as exploited in the wild in December 2013.

    Source:Danilo PC
    Published:20 Apr 2010
    3.7
    Low

    CVE-2013-5147

    Last Modified: 15 Oct 2013

    Passcode Lock in Apple iOS before 7 does not properly manage the lock state, which allows physically proximate attackers to bypass an intended passcode requirement by leveraging a race condition involving phone calls and ejection of a SIM card.

    Source:Vulnerability-Lab
    Published:19 Sept 2013
    5.9
    Medium

    CVE-2013-5123

    Last Modified: 14 Jan 2013

    The mirroring support (-M, --use-mirrors) in Python Pip before 1.5 uses insecure DNS querying and authenticity checks which allows attackers to perform man-in-the-middle attacks.

    Source:LiquidWorm
    Published:31 Jul 2013
    7.5
    High

    CVE-2013-5121

    Last Modified: 8 Aug 2013

    SQL injection vulnerability in PHPFox before 3.6.0 (build6) allows remote attackers to execute arbitrary SQL commands via the search[sort_by] parameter to user/browse/view_/.

    Source:Matias Fontanini
    Published:14 Aug 2013
    7.5
    High

    CVE-2013-5120

    Last Modified: 8 Aug 2013

    SQL injection vulnerability in PHPFox before 3.6.0 (build4) allows remote attackers to execute arbitrary SQL commands via the search[gender] parameter to user/browse/view_/.

    Source:Matias Fontanini
    Published:14 Aug 2013