5
    Medium

    CVE-2013-3827

    Last Modified: 24 Nov 2015

    Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 2.1.1, 3.0.1, and 3.1.2; the Oracle JDeveloper component in Oracle Fusion Middleware 11.1.2.3.0, 11.1.2.4.0, and 12.1.2.0.0; and the Oracle WebLogic Server component in Oracle Fusion Middleware 10.3.6.0 and 12.1.1 allows remote attackers to affect confidentiality via unknown vectors related to Java Server Faces or Web Container.

    Source:Alex Kouzemtchenko
    Published:16 Oct 2013
    3.5
    Low

    CVE-2013-3803

    Last Modified: 2 Aug 2013

    Unspecified vulnerability in the Hyperion BI+ component in Oracle Hyperion 11.1.1.3, 11.1.1.4.107 and earlier, 11.1.2.1.129 and earlier, and 11.1.2.2.305 and earlier allows remote authenticated users to affect confidentiality via unknown vectors related to Intelligence Service.

    Source:Richard Warren
    Published:17 Jul 2013
    3.8
    Low

    CVE-2013-3792

    Last Modified: 2 Nov 2015

    Unspecified vulnerability in the Oracle VM VirtualBox component in Oracle Virtualization VirtualBox prior to 3.2.18, 4.0.20, 4.1.28, and 4.2.18 allows local users to affect availability via unknown vectors related to Core.

    Source:Thomas Dreibholz
    Published:16 Oct 2013
    5.5
    Medium

    CVE-2013-3763

    Last Modified: 26 Aug 2013

    Unspecified vulnerability in the Oracle Endeca Server component in Oracle Fusion Middleware 7.4.0 and 7.5.1.1 allows remote authenticated users to affect confidentiality and integrity via unknown vectors, a different vulnerability than CVE-2013-3764.

    Source:Metasploit
    Published:17 Jul 2013
    5
    Medium

    CVE-2013-3739

    Last Modified: 24 Oct 2016

    Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the mapname parameter in a show_config action.

    Source:Anthony Dubuissez
    Published:5 Jun 2014
    6.8
    Medium

    CVE-2013-3729

    Last Modified: 5 Jul 2013

    Multiple cross-site request forgery (CSRF) vulnerabilities in Kasseler CMS before 2 r1232 allow remote attackers to hijack the authentication of administrators for requests that conduct SQL injection attacks via the (1) groups[] parameter in a send action in the sendmail module or (2) query parameter in a sql_query action in the database module to admin.php, related to CVE-2013-3727.

    Source:High-Tech Bridge SA
    Published:13 Mar 2014
    3.5
    Low

    CVE-2013-3728

    Last Modified: 5 Jul 2013

    Cross-site scripting (XSS) vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users with permissions to create categories to inject arbitrary web script or HTML via the cat parameter in an admin_new_category action to admin.php.

    Source:High-Tech Bridge SA
    Published:13 Mar 2014
    7.5
    High

    CVE-2013-3727

    Last Modified: 5 Jul 2013

    SQL injection vulnerability in Kasseler CMS before 2 r1232 allows remote authenticated users to execute arbitrary SQL commands via the groups[] parameter to admin.php. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to execute arbitrary SQL commands.

    Source:High-Tech Bridge SA
    Published:13 Mar 2014
    5
    Medium

    CVE-2013-3724

    Last Modified: 30 May 2013

    The mk_request_header_process function in mk_request.c in Monkey 1.1.1 allows remote attackers to cause a denial of service (thread crash and service outage) via a '\0' character in an HTTP request.

    Source:Doug Prostko
    Published:31 Jul 2013
    7.5
    High

    CVE-2013-3721

    Last Modified: 1 Dec 2016

    SQL injection vulnerability in awards.php in PsychoStats 3.2.2b allows remote attackers to execute arbitrary SQL commands via the d parameter.

    Source:Mohamed from ALG
    Published:31 May 2013
    7.5
    High

    CVE-2013-3691

    Last Modified: 13 Jun 2013

    AirLive POE-2600HD allows remote attackers to cause a denial of service (device reset) via a long URL.

    Source:Sánchez_ Lopez_ Castillo
    Published:11 Dec 2019
    6.8
    Medium

    CVE-2013-3690

    Last Modified: 31 Oct 2015

    Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.1.0.8 and earlier, allows remote attackers to hijack the authentication of administrators for requests that add users.

    Source:Castillo
    Published:1 Oct 2013
    7.8
    High

    CVE-2013-3687

    Last Modified: 13 Jun 2013

    AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models use cleartext to store sensitive information, which allows attackers to obtain passwords, user names, and other sensitive information by reading an unspecified backup file.

    Source:Sánchez_ Lopez_ Castillo
    Published:11 Oct 2013
    10
    Critical

    CVE-2013-3686

    Last Modified: 13 Jun 2013

    cgi-bin/operator/param in AirLive WL2600CAM and possibly other camera models allows remote attackers to obtain the administrator password via a list action.

    Source:Sánchez_ Lopez_ Castillo
    Published:11 Oct 2013
    9.8
    Critical

    CVE-2013-3684

    Last Modified: 31 Oct 2015

    NextGEN Gallery plugin before 1.9.13 for WordPress: ngggallery.php file upload

    Source:Marcos Garcia
    Published:11 Feb 2020
    9.3
    Critical

    CVE-2013-3664

    Last Modified: 12 Apr 2025

    Trimble SketchUp (formerly Google SketchUp) before 2013 (13.0.3689) allows remote attackers to execute arbitrary code via a crafted color palette table in a MAC Pict texture, which triggers an out-of-bounds stack write. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-3662. NOTE: this issue was SPLIT due to different affected products and codebases (ADT1); CVE-2013-7388 has been assigned to the paintlib issue.

    Published:1 Jul 2014
    4.9
    Medium

    CVE-2013-3661

    Last Modified: 21 May 2013

    The EPATHOBJ::bFlatten function in win32k.sys in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT does not check whether linked-list traversal is continually accessing the same list member, which allows local users to cause a denial of service (infinite traversal) via vectors that trigger a crafted PATHRECORD chain.

    Source:Tavis Ormandy
    Published:24 May 2013
    7.8
    High

    CVE-2013-3660

    Last Modified: 21 May 2013

    The EPATHOBJ::pprFlattenRec function in win32k.sys in the kernel-mode drivers in Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, and Windows Server 2012 does not properly initialize a pointer for the next object in a certain list, which allows local users to obtain write access to the PATHRECORD chain, and consequently gain privileges, by triggering excessive consumption of paged memory and then making many FlattenPath function calls, aka "Win32k Read AV Vulnerability."

    Source:Tavis Ormandy
    Published:24 May 2013
    7.5
    High

    CVE-2013-3651

    Last Modified: 11 Apr 2025

    LOCKON EC-CUBE 2.11.2 through 2.12.4 allows remote attackers to conduct unspecified PHP code-injection attacks via a crafted string, related to data/class/SC_CheckError.php and data/class/SC_FormParam.php.

    Published:29 Jun 2013
    4.3
    Medium

    CVE-2013-3639

    Last Modified: 2 Nov 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Xaraya 2.4.0-b1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) id, (2) interface, (3) name, or (4) tabmodule parameter to index.php.

    Source:High-Tech Bridge
    Published:5 Feb 2014
    8.8
    High

    CVE-2013-3632

    Last Modified: 31 Oct 2013

    The Cron service in rpc.php in OpenMediaVault allows remote authenticated users to execute cron jobs as arbitrary users and execute arbitrary commands via the username parameter.

    Source:Metasploit
    Published:29 Sept 2014
    6
    Medium

    CVE-2013-3631

    Last Modified: 31 Oct 2013

    NAS4Free 9.1.0.1.804 and earlier allows remote authenticated users to execute arbitrary PHP code via a request to exec.php, aka the "Advanced | Execute Command" feature. NOTE: this issue might not be a vulnerability, since it appears to be part of legitimate, intentionally-exposed functionality by the developer and is allowed within the intended security policy.

    Source:Metasploit
    Published:2 Nov 2013
    4.6
    Medium

    CVE-2013-3630

    Last Modified: 31 Oct 2013

    Moodle through 2.5.2 allows remote authenticated administrators to execute arbitrary programs by configuring the aspell pathname and then triggering a spell-check operation within the TinyMCE editor.

    Source:Metasploit
    Published:1 Nov 2013
    8.8
    High

    CVE-2013-3629

    Last Modified: 2 Nov 2013

    ISPConfig 3.0.5.2 has Arbitrary PHP Code Execution

    Source:Metasploit
    Published:7 Feb 2020
    8.8
    High

    CVE-2013-3628

    Last Modified: 31 Oct 2013

    Zabbix 2.0.9 has an Arbitrary Command Execution Vulnerability

    Source:Metasploit
    Published:7 Feb 2020
    10
    Critical

    CVE-2013-3623

    Last Modified: 18 Nov 2013

    Multiple stack-based buffer overflows in cgi/close_window.cgi in the web interface in the Intelligent Platform Management Interface (IPMI) with firmware before 3.15 (SMT_X9_315) on Supermicro X9 generation motherboards allow remote attackers to execute arbitrary code via the (1) sess_sid or (2) ACT parameter.

    Source:Metasploit
    Published:10 Dec 2013
    3.5
    Low

    CVE-2013-3617

    Last Modified: 27 Nov 2015

    The XML API in Openbravo ERP 2.5, 3.0, and earlier allows remote authenticated users to read arbitrary files via an XML document with an external entity declaration in conjunction with an entity reference to /ws/dal/ADUser or other /ws/dal/XXX interfaces, related to an XML External Entity (XXE) issue.

    Source:Tod Beardsley
    Published:2 Nov 2013
    7.8
    High

    CVE-2013-3615

    Last Modified: 18 Nov 2013

    Dahua DVR appliances use a password-hash algorithm with a short hash length, which makes it easier for context-dependent attackers to discover cleartext passwords via a brute-force attack.

    Source:Jake Reynolds
    Published:17 Sept 2013
    9.3
    Critical

    CVE-2013-3614

    Last Modified: 18 Nov 2013

    Dahua DVR appliances have a small value for the maximum password length, which makes it easier for remote attackers to obtain access via a brute-force attack.

    Source:Jake Reynolds
    Published:17 Sept 2013
    7.8
    High

    CVE-2013-3613

    Last Modified: 18 Nov 2013

    Dahua DVR appliances do not properly restrict UPnP requests, which makes it easier for remote attackers to obtain access via vectors involving a replay attack against the TELNET port.

    Source:Jake Reynolds
    Published:17 Sept 2013
    10
    Critical

    CVE-2013-3612

    Last Modified: 18 Nov 2013

    Dahua DVR appliances have a hardcoded password for (1) the root account and (2) an unspecified "backdoor" account, which makes it easier for remote attackers to obtain administrative access via authorization requests involving (a) ActiveX, (b) a standalone client, or (c) unknown other vectors.

    Source:Jake Reynolds
    Published:17 Sept 2013
    5
    Medium

    CVE-2013-3597

    Last Modified: 17 Nov 2015

    servlet/CollectionListServlet in SearchBlox before 7.5 build 1 allows remote attackers to read usernames and passwords via a getList action.

    Source:Ricky Roane Jr
    Published:28 Aug 2013
    8.8
    High

    CVE-2013-3591

    Last Modified: 4 Oct 2017

    vTiger CRM 5.3 and 5.4: 'files' Upload Folder Arbitrary PHP Code Execution Vulnerability

    Source:Metasploit
    Published:7 Feb 2020
    7.6
    High

    CVE-2013-3586

    Last Modified: 21 Aug 2013

    Samsung Web Viewer for Samsung DVR devices allows remote attackers to bypass authentication via an arbitrary SessionID value in a cookie.

    Source:Andrea Fabrizi
    Published:28 Aug 2013
    5
    Medium

    CVE-2013-3585

    Last Modified: 21 Aug 2013

    Samsung Web Viewer for Samsung DVR devices stores credentials in cleartext, which allows context-dependent attackers to obtain sensitive information via vectors involving (1) direct access to a file or (2) the user-setup web page.

    Source:Andrea Fabrizi
    Published:28 Aug 2013
    9
    Critical

    CVE-2013-3576

    Last Modified: 24 Jun 2013

    ginkgosnmp.inc in HP System Management Homepage (SMH) allows remote authenticated users to execute arbitrary commands via shell metacharacters in the PATH_INFO to smhutil/snmpchp.php.en.

    Source:Metasploit
    Published:14 Jun 2013
    5
    Medium

    CVE-2013-3575

    Last Modified: 24 Oct 2016

    hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows remote attackers to include arbitrary hpdiags/frontend2/help/ .html files via the path parameter.

    Source:Markus Wulftange
    Published:14 Jun 2013
    7.8
    High

    CVE-2013-3574

    Last Modified: 29 Oct 2015

    Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers to write data to arbitrary files via a full pathname in the argument to the devicePath (aka mount) parameter.

    Source:Markus Wulftange
    Published:14 Jun 2013
    8.8
    High

    CVE-2013-3568

    Last Modified: 23 Sept 2013

    Cross-site request forgery (CSRF) vulnerability in Cisco Linksys WRT110 allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.

    Source:Metasploit
    Published:6 Feb 2020
    7.5
    High

    CVE-2013-3563

    Last Modified: 31 May 2013

    Stack-based buffer overflow in db_netserver in Lianja SQL Server before 1.0.0RC5.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a crafted string to TCP port 8001.

    Source:Metasploit
    Published:4 Jul 2013
    8.8
    High

    CVE-2013-3543

    Last Modified: 13 Jun 2013

    The AXIS Media Control (AMC) ActiveX control (AxisMediaControlEmb.dll) 6.2.10.11 for AXIS network cameras allows remote attackers to create or overwrite arbitrary files via a file path to the (1) StartRecord, (2) SaveCurrentImage, or (3) StartRecordMedia methods.

    Source:Javier Repiso Sánchez
    Published:4 Oct 2013
    7.8
    High

    CVE-2013-3541

    Last Modified: 13 Jun 2013

    Directory traversal vulnerability in cgi-bin/admin/fileread in AirLive WL2600CAM and possibly other camera models allows remote attackers to read arbitrary files via a .. (dot dot) in the READ.filePath parameter.

    Source:Sánchez_ Lopez_ Castillo
    Published:4 Oct 2013
    6.8
    Medium

    CVE-2013-3540

    Last Modified: 13 Jun 2013

    Cross-site request forgery (CSRF) vulnerability in cgi-bin/admin/usrgrp.cgi in AirLive POE2600HD, POE250HD, POE200HD, OD-325HD, OD-2025HD, OD-2060HD, POE100HD, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.

    Source:Sánchez_ Lopez_ Castillo
    Published:4 Oct 2013
    6.8
    Medium

    CVE-2013-3539

    Last Modified: 31 Oct 2015

    Cross-site request forgery (CSRF) vulnerability in the command/user.cgi in Sony SNC CH140, SNC CH180, SNC CH240, SNC CH280, SNC DH140, SNC DH140T, SNC DH180, SNC DH240, SNC DH240T, SNC DH280, and possibly other camera models allows remote attackers to hijack the authentication of administrators for requests that add users.

    Source:Castillo
    Published:1 Oct 2013
    4.3
    Medium

    CVE-2013-3538

    Last Modified: 18 Oct 2015

    Multiple cross-site scripting (XSS) vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to inject arbitrary web script or HTML via the (1) id_post or (2) pg parameter.

    Source:Chiekh Bouchenafa
    Published:13 May 2013
    7.5
    High

    CVE-2013-3537

    Last Modified: 18 Oct 2015

    Multiple SQL injection vulnerabilities in todooforum.php in Todoo Forum 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) id_post or (2) pg parameter.

    Source:Chiekh Bouchenafa
    Published:13 May 2013
    7.5
    High

    CVE-2013-3536

    Last Modified: 24 Jan 2017

    SQL injection vulnerability in the gp_LoadUserFromHash function in functions_hash.php in the Group Pay module 1.5 and earlier for WHMCS allows remote attackers to execute arbitrary SQL commands via the hash parameter.

    Source:HJauditing Employee Tim
    Published:13 May 2013
    4.3
    Medium

    CVE-2013-3535

    Last Modified: 15 Apr 2013

    Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_email, (2) header_title, (3) site_title parameter to admin/settings; (4) recaptcha_private or (5) recaptcha_public parameter to admin/captcha_settings; (6) fb_appid, (7) fp_secret, (8) tw_consumer_key, or (9) tw_consumer_secret parameter to admin/social_settings; (10) slug parameter to admin/gallery/save_item_settings; or (11) item_link parameter to admin/edit_menu_item_ajax. NOTE: this issue might be resultant from CSRF.

    Source:LiquidWorm
    Published:13 May 2013
    7.5
    High

    CVE-2013-3532

    Last Modified: 15 Oct 2015

    SQL injection vulnerability in settings.php in the Web Dorado Spider Video Player plugin 2.1 for WordPress allows remote attackers to execute arbitrary SQL commands via the theme parameter.

    Source:Ashiyane Digital Security Team
    Published:10 May 2013
    7.5
    High

    CVE-2013-3531

    Last Modified: 26 May 2013

    SQL injection vulnerability in meneger.php in RadioCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the playlist_id parameter.

    Source:Rooster(XEKA)
    Published:10 May 2013