NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40212 | CVE-2013-4649 | Cross-site scripting (XSS) vulnerability in DotNetNuke (DNN) before 6.2.9 and 7.x before 7.1.1 allows remote attackers to inject arbitrary web script or HTML via the __dnnVariable parameter to the default URI. | 2 | 4.3 | Medium | 2017-01-18 | 2014-03-13 | View | |
40468 | CVE-2013-4998 | phpMyAdmin 3.5.x before 3.5.8.2 and 4.0.x before 4.0.4.2 allows remote attackers to obtain sensitive information via an invalid request, which reveals the installation path in an error message, related to pmd_common.php and other files. | 2 | 5 | Medium | 2017-01-18 | 2013-07-31 | View | |
40724 | CVE-2013-5426 | Session fixation vulnerability in IBM InfoSphere Master Data Management - Collaborative Edition 10.x before 10.1 IF5 and 11.0 before IF1 and InfoSphere Master Data Management Server for Product Information Management 9.x before 9.1 IF11 allows remote authenticated users to hijack web sessions via unspecified vectors. | 2 | 4.9 | Medium | 2017-01-18 | 2013-12-20 | View | |
40980 | CVE-2013-5748 | Cross-site request forgery (CSRF) vulnerability in management/prioritize_planning.php in SimpleRisk before 20130916-001 allows remote attackers to hijack the authentication of users for requests that add projects via an add_project action. | 2 | 6.8 | Medium | 2017-01-18 | 2014-05-13 | View | |
41236 | CVE-2013-6034 | The firmware on GateHouse; Harris BGAN RF-7800B-VU204 and BGAN RF-7800B-DU204; Hughes Network Systems 9201, 9450, and 9502; Inmarsat; Japan Radio JUE-250 and JUE-500; and Thuraya IP satellite terminals has hardcoded credentials, which makes it easier for attackers to obtain unspecified login access via unknown vectors. | 2 | 10 | High | 2017-01-18 | 2014-02-04 | View |
Page 1407 of 17672, showing 5 records out of 88360 total, starting on record 7031, ending on 7035