4.3
    Medium

    CVE-2013-5118

    Last Modified: 25 Sept 2013

    Cross-site scripting (XSS) vulnerability in the Good for Enterprise app before 2.2.4.1659 for iOS allows remote attackers to inject arbitrary web script or HTML via an HTML e-mail message.

    Source:Mario
    Published:25 Sept 2013
    7.5
    High

    CVE-2013-5117

    Last Modified: 16 Aug 2013

    SQL injection vulnerability in the RSS page (DNNArticleRSS.aspx) in the ZLDNN DNNArticle module before 10.1 for DotNetNuke allows remote attackers to execute arbitrary SQL commands via the categoryid parameter.

    Source:Sajjad Pourali
    Published:12 Mar 2014
    2.6
    Low

    CVE-2013-5099

    Last Modified: 21 Jul 2013

    Cross-site scripting (XSS) vulnerability in article.php in Anchor CMS 0.9.1, when comments are enabled, allows remote attackers to inject arbitrary web script or HTML via the Name field. NOTE: some sources have reported that comments.php is vulnerable, but certain functions from comments.php are used by article.php.

    Source:DURAKIBOX
    Published:9 Aug 2013
    4.3
    Medium

    CVE-2013-5094

    Last Modified: 30 Sept 2015

    Cross-site scripting (XSS) vulnerability in index.exp in McAfee Vulnerability Manager 7.5 allows remote attackers to inject arbitrary web script or HTML via the cert_cn cookie parameter.

    Source:Asheesh Anaconda
    Published:28 Jan 2014
    6.8
    Medium

    CVE-2013-5093

    Last Modified: 21 Aug 2013

    The renderLocalView function in render/views.py in graphite-web in Graphite 0.9.5 through 0.9.10 uses the pickle Python module unsafely, which allows remote attackers to execute arbitrary code via a crafted serialized object.

    Source:Metasploit
    Published:27 Sept 2013
    4.3
    Medium

    CVE-2013-5092

    Last Modified: 15 Nov 2015

    Cross-site scripting (XSS) vulnerability in afa/php/Login.php in AlgoSec Firewall Analyzer 6.1-b86 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.

    Source:Asheesh kumar Mani Tripathi
    Published:29 Jan 2014
    6.5
    Medium

    CVE-2013-5091

    Last Modified: 4 Oct 2017

    SQL injection vulnerability in CalendarCommon.php in vTiger CRM 5.4.0 and possibly earlier allows remote authenticated users to execute arbitrary SQL commands via the onlyforuser parameter in an index action to index.php. NOTE: this issue might be a duplicate of CVE-2011-4559.

    Source:High-Tech Bridge SA
    Published:4 Oct 2013
    7.8
    High

    CVE-2013-5065

    Last Modified: 15 Apr 2017

    NDProxy.sys in the kernel in Microsoft Windows XP SP2 and SP3 and Server 2003 SP2 allows local users to gain privileges via a crafted application, as exploited in the wild in November 2013.

    Source:ryujin
    Published:27 Nov 2013
    6.9
    Medium

    CVE-2013-5058

    Last Modified: 31 Mar 2017

    Integer overflow in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows local users to gain privileges via a crafted application, aka "Win32k Integer Overflow Vulnerability."

    Source:Core Security
    Published:11 Dec 2013
    6.2
    Medium

    CVE-2013-5045

    Last Modified: 27 Jun 2014

    Microsoft Internet Explorer 10 and 11 allows local users to bypass the Protected Mode protection mechanism, and consequently gain privileges, by leveraging the ability to execute sandboxed code, aka "Internet Explorer Elevation of Privilege Vulnerability."

    Source:Metasploit
    Published:11 Dec 2013
    5.4
    Medium

    CVE-2013-5039

    Last Modified: 8 Nov 2013

    Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of administrators for requests that change the WiFi Security field to Deactivated via the WifiSecurity parameter.

    Source:Oz Elisyan
    Published:30 Dec 2013
    5.8
    Medium

    CVE-2013-5038

    Last Modified: 8 Nov 2013

    The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session.

    Source:Oz Elisyan
    Published:30 Dec 2013
    3.3
    Low

    CVE-2013-5037

    Last Modified: 8 Nov 2013

    The HOT HOTBOX router with software 2.1.11 has a default WPS PIN of 12345670, which makes it easier for remote attackers to obtain the WPA or WPA2 pre-shared key via EAP messages.

    Source:Oz Elisyan
    Published:30 Dec 2013
    7.5
    High

    CVE-2013-5036

    Last Modified: 12 Aug 2013

    The Square Squash allows remote attackers to execute arbitrary code via a YAML document in the (1) namespace parameter to the deobfuscation function or (2) sourcemap parameter to the sourcemap function in app/controllers/api/v1_controller.rb.

    Source:Metasploit
    Published:27 May 2014
    7.2
    High

    CVE-2013-5030

    Last Modified: 19 Nov 2013

    Ruckus Wireless Zoneflex 2942 devices with firmware 9.6.0.0.267 allow remote attackers to bypass authentication, and subsequently access certain configuration/ and maintenance/ scripts, by constructing a crafted URI after receiving an authentication error for an arbitrary login attempt.

    Source:myexploit
    Published:16 Oct 2013
    6.5
    Medium

    CVE-2013-5028

    Last Modified: 15 Nov 2015

    SQL injection vulnerability in IT/hardware-list.dll in Kwoksys Kwok Information Server before 2.8.5 allows remote authenticated users to execute arbitrary SQL commands via the (1) hardwareType, (2) hardwareStatus, or (3) hardwareLocation parameter in a search command.

    Source:Yogesh Phadtare
    Published:11 Oct 2013
    4.3
    Medium

    CVE-2013-5020

    Last Modified: 26 Sept 2016

    Multiple cross-site scripting (XSS) vulnerabilities in bb_admin.php in MiniBB before 3.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) forum_name, (2) forum_group, (3) forum_icon, or (4) forum_desc parameter. NOTE: the whatus vector is already covered by CVE-2008-2066.

    Source:Netsparker
    Published:31 Jul 2013
    10
    Critical

    CVE-2013-5019

    Last Modified: 15 Aug 2013

    Stack-based buffer overflow in Ultra Mini HTTPD 1.21 allows remote attackers to execute arbitrary code via a long resource name in an HTTP request.

    Source:Metasploit
    Published:31 Jul 2013
    6.5
    Medium

    CVE-2013-5015

    Last Modified: 26 Feb 2014

    SQL injection vulnerability in the management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Source:Metasploit
    Published:14 Feb 2014
    7.5
    High

    CVE-2013-5014

    Last Modified: 26 Feb 2014

    The management console in Symantec Endpoint Protection Manager (SEPM) 11.0 before 11.0.7405.1424 and 12.1 before 12.1.4023.4080, and Symantec Protection Center Small Business Edition 12.x before 12.1.4023.4080, allows remote attackers to read arbitrary files via XML data containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.

    Source:Metasploit
    Published:14 Feb 2014
    4.3
    Medium

    CVE-2013-5006

    Last Modified: 2 Aug 2013

    main_internet.php on the Western Digital My Net N600 and N750 with firmware 1.03.12 and 1.04.16, and the N900 and N900C with firmware 1.05.12, 1.06.18, and 1.06.28, allows remote attackers to discover the cleartext administrative password by reading the "var pass=" line within the HTML source code.

    Source:Kyle Lovett
    Published:31 Jul 2013
    9.3
    Critical

    CVE-2013-4988

    Last Modified: 11 Dec 2013

    Stack-based buffer overflow in IcoFX 2.5 and earlier allows remote attackers to execute arbitrary code via a long idCount value in an ICONDIR structure in an ICO file. NOTE: some of these details are obtained from third party information.

    Source:Core Security
    Published:13 Dec 2013
    8.5
    High

    CVE-2013-4987

    Last Modified: 2 Oct 2013

    PineApp Mail-SeCure before 3.70 allows remote authenticated users to gain privileges by leveraging console access and providing shell metacharacters in a "system ping" command.

    Source:Core Security
    Published:8 Nov 2013
    7.5
    High

    CVE-2013-4985

    Last Modified: 8 Nov 2013

    Multiple Vivotek IP Cameras remote authentication bypass that could allow access to the video stream

    Source:Core Security
    Published:27 Dec 2019
    7.2
    High

    CVE-2013-4984

    Last Modified: 17 Sept 2013

    The close_connections function in /opt/cma/bin/clear_keys.pl in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows local users to gain privileges via shell metacharacters in the second argument.

    Source:Metasploit
    Published:10 Sept 2013
    10
    Critical

    CVE-2013-4983

    Last Modified: 27 Oct 2016

    The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to end-user/index.php.

    Source:Metasploit
    Published:10 Sept 2013
    9.8
    Critical

    CVE-2013-4982

    Last Modified: 29 Aug 2013

    AVTECH AVN801 DVR has a security bypass via the administration login captcha

    Source:Core Security
    Published:27 Dec 2019
    9
    Critical

    CVE-2013-4981

    Last Modified: 29 Aug 2013

    Buffer overflow in cgi-bin/user/Config.cgi in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the Network.SMTP.Receivers parameter.

    Source:Core Security
    Published:3 Mar 2014
    9
    Critical

    CVE-2013-4980

    Last Modified: 29 Aug 2013

    Buffer overflow in the RTSP Packet Handler in AVTECH AVN801 DVR with firmware 1017-1003-1009-1003 and earlier, and possibly other devices, allows remote attackers to cause a denial of service (device crash) and possibly execute arbitrary code via a long string in the URI in an RTSP SETUP request.

    Source:Core Security
    Published:3 Mar 2014
    9.3
    Critical

    CVE-2013-4978

    Last Modified: 21 Nov 2015

    Stack-based buffer overflow in AloahaPDFViewer 5.0.0.7 and earlier in Aloaha PDF Suite FREE allows remote attackers to execute arbitrary code via a crafted PDF file.

    Source:Marcos Accossatto
    Published:5 Feb 2014
    10
    Critical

    CVE-2013-4977

    Last Modified: 7 Aug 2013

    Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other devices, allows remote attackers to cause a denial of service (device crash and reboot) and possibly execute arbitrary code via a long string in the Range header field in an RTSP transaction.

    Source:Core Security
    Published:3 Mar 2014
    9.8
    Critical

    CVE-2013-4976

    Last Modified: 7 Aug 2013

    Hikvision DS-2CD7153-E IP Camera has security bypass via hardcoded credentials

    Source:Core Security
    Published:27 Dec 2019
    8.8
    High

    CVE-2013-4975

    Last Modified: 7 Aug 2013

    Hikvision DS-2CD7153-E IP Camera has Privilege Escalation

    Source:Core Security
    Published:27 Dec 2019
    2.6
    Low

    CVE-2013-4954

    Last Modified: 6 Nov 2015

    Multiple cross-site scripting (XSS) vulnerabilities in wp-login.php in the Genetech Solutions Pie-Register plugin before 1.31 for WordPress, when "Allow New Registrations to set their own Password" is enabled, allow remote attackers to inject arbitrary web script or HTML via the (1) pass1 or (2) pass2 parameter in a register action. NOTE: some of these details are obtained from third party information.

    Source:gravitylover
    Published:29 Jul 2013
    7.5
    High

    CVE-2013-4953

    Last Modified: 29 Jun 2013

    SQL injection vulnerability in play.php in Top Games Script 1.2 allows remote attackers to execute arbitrary SQL commands via the gid parameter.

    Source:AtT4CKxT3rR0r1ST
    Published:29 Jul 2013
    7.5
    High

    CVE-2013-4952

    Last Modified: 24 Jun 2013

    SQL injection vulnerability in functions/global.php in Elemata CMS RC 3.0 allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:CWH Underground
    Published:29 Jul 2013
    4.3
    Medium

    CVE-2013-4951

    Last Modified: 5 Nov 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Mintboard 0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) pass parameter in views/login.php or (3) name or (4) pass parameter in views/signup.php.

    Source:Canberk BOLAT
    Published:29 Jul 2013
    4.3
    Medium

    CVE-2013-4950

    Last Modified: 10 Jul 2013

    Cross-site scripting (XSS) vulnerability in view.php in Machform 2 allows remote attackers to inject arbitrary web script or HTML via the element_2 parameter.

    Source:Yashar shahinzadeh
    Published:29 Jul 2013
    6.8
    Medium

    CVE-2013-4949

    Last Modified: 10 Jul 2013

    Unrestricted file upload vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary PHP code by uploading a PHP file, then accessing it via a direct request to the file in the upload form's directory in data/.

    Source:Yashar shahinzadeh
    Published:29 Jul 2013
    7.5
    High

    CVE-2013-4948

    Last Modified: 10 Jul 2013

    SQL injection vulnerability in view.php in Machform 2 allows remote attackers to execute arbitrary SQL commands via the element_2 parameter.

    Source:Yashar shahinzadeh
    Published:29 Jul 2013
    4.3
    Medium

    CVE-2013-4946

    Last Modified: 13 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to inject arbitrary web script or HTML via the (1) SelTab parameter to QV_admin.aspx, the (2) CallBack parameter to QV_grid.aspx, or the (3) HelpPage parameter to commonhelp.aspx.

    Source:Nuri Fattah
    Published:29 Jul 2013
    7.5
    High

    CVE-2013-4945

    Last Modified: 13 Jul 2013

    Multiple SQL injection vulnerabilities in BMC Service Desk Express (SDE) 10.2.1.95 allow remote attackers to execute arbitrary SQL commands via the (1) ASPSESSIONIDASSRATTQ, (2) TABLE_WIDGET_1, (3) TABLE_WIDGET_2, (4) browserDateTimeInfo, or (5) browserNumberInfo cookie parameter to DashBoardGUI.aspx; or the (6) UID parameter to login.aspx.

    Source:Nuri Fattah
    Published:29 Jul 2013
    5
    Medium

    CVE-2013-4900

    Last Modified: 17 Nov 2015

    Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote attackers to read arbitrary files via a ..%5c (dot dot encoded backslash) in a GET request.

    Source:High-Tech Bridge
    Published:9 Sept 2013
    6.5
    Medium

    CVE-2013-4898

    Last Modified: 6 Aug 2013

    Unrestricted file upload vulnerability in the user profile page feature in the Timeline Plugin 4.2.5p9 for SocialEngine allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in public/temporary/timeline/.

    Source:spyk2r
    Published:29 Jan 2014
    7.8
    High

    CVE-2013-4890

    Last Modified: 23 Jul 2013

    The DMCRUIS/0.1 web server on the Samsung PS50C7700 TV allows remote attackers to cause a denial of service (daemon crash) via a long URI to TCP port 5600.

    Source:Malik Mesellem
    Published:22 Jul 2013
    6.8
    Medium

    CVE-2013-4889

    Last Modified: 18 Nov 2015

    Multiple cross-site request forgery (CSRF) vulnerabilities in index.php in Digital Signage Xibo 1.4.2 allow remote attackers to hijack the authentication of administrators for requests that (1) add a new administrator via the AddUser action or (2) conduct cross-site scripting (XSS) attacks, as demonstrated by CVE-2013-4888.

    Source:Jacob Holcomb
    Published:29 Jan 2014
    4.3
    Medium

    CVE-2013-4888

    Last Modified: 18 Nov 2015

    Cross-site scripting (XSS) vulnerability in index.php in Digital Signage Xibo 1.4.2 allows remote attackers to inject arbitrary web script or HTML via the layout parameter in the layout page.

    Source:Jacob Holcomb
    Published:29 Jan 2014
    6.8
    Medium

    CVE-2013-4885

    Last Modified: 17 Nov 2015

    The http-domino-enum-passwords.nse script in NMap before 6.40, when domino-enum-passwords.idpath is set, allows remote servers to upload "arbitrarily named" files via a crafted FullName parameter in a response, as demonstrated using directory traversal sequences.

    Source:Piotr Duszynski
    Published:7 Aug 2013
    4.3
    Medium

    CVE-2013-4884

    Last Modified: 7 Aug 2013

    Cross-site scripting (XSS) vulnerability in McAfee SuperScan 4.0 allows remote attackers to inject arbitrary web script or HTML via UTF-7 encoded sequences in a server response, which is not properly handled in the SuperScan HTML report.

    Source:Trustwave's SpiderLabs
    Published:21 Jan 2014
    4.3
    Medium

    CVE-2013-4883

    Last Modified: 13 Jul 2013

    Multiple cross-site scripting (XSS) vulnerabilities in McAfee ePolicy Orchestrator 4.6.6 and earlier, and the ePO Extension for the McAfee Agent (MA) 4.5 through 4.6, allow remote attackers to inject arbitrary web script or HTML via the (1) instanceId parameter core/loadDisplayType.do; (2) instanceId or (3) monitorUrl parameter to console/createDashboardContainer.do; uid parameter to (4) ComputerMgmt/sysDetPanelBoolPie.do or (5) ComputerMgmt/sysDetPanelSummary.do; (6) uid, (7) orion.user.security.token, or (8) ajaxMode parameter to ComputerMgmt/sysDetPanelQry.do; or (9) uid, (10) orion.user.security.token, or (11) ajaxMode parameter to ComputerMgmt/sysDetPanelSummary.do.

    Source:Nuri Fattah
    Published:21 Jul 2013