NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
40941 | CVE-2013-5692 | Directory traversal vulnerability in X2Engine X2CRM before 3.5 allows remote authenticated administrators to include and execute arbitrary local files via a .. (dot dot) in the file parameter to index.php/admin/translationManager. | 2 | 8.5 | High | 2017-01-18 | 2013-10-01 | View | |
41197 | CVE-2013-5992 | Cross-site scripting (XSS) vulnerability in the displaySystemError function in html/handle_error.php in LOCKON EC-CUBE 2.11.0 through 2.11.5 allows remote attackers to inject arbitrary web script or HTML by leveraging incorrect handling of error-message output. | 2 | 4.3 | Medium | 2017-01-18 | 2013-11-21 | View | |
41453 | CVE-2013-6395 | Cross-site scripting (XSS) vulnerability in header.php in Ganglia Web 3.5.8 and 3.5.10 allows remote attackers to inject arbitrary web script or HTML via the host_regex parameter to the default URI, which is processed by get_context.php. | 2 | 4.3 | Medium | 2017-01-18 | 2013-12-27 | View | |
41709 | CVE-2013-6830 | admin/confnetworking.html in PineApp Mail-SeCure 3.70 and earlier on 5099SK and earlier platforms allows remote attackers to execute arbitrary commands via shell metacharacters in the nsserver parameter during an nslookup operation. | 2 | 7.5 | High | 2017-01-18 | 2013-11-24 | View | |
41965 | CVE-2013-7221 | The automatic screen lock functionality in GNOME Shell (aka gnome-shell) before 3.10 does not prevent access to the "Enter a Command" dialog, which allows physically proximate attackers to execute arbitrary commands by leveraging an unattended workstation. | 2 | 4.6 | Medium | 2017-01-18 | 2014-04-29 | View |
Page 16430 of 17672, showing 5 records out of 88360 total, starting on record 82146, ending on 82150