NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
37895 | CVE-2013-1733 | Cross-site request forgery (CSRF) vulnerability in process_bug.cgi in Bugzilla 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that modify bugs via vectors involving a midair-collision token. | 2 | 6.8 | Medium | 2017-01-18 | 2013-10-24 | View | |
38151 | CVE-2013-2036 | Cross-site scripting (XSS) vulnerability in the Filebrowser module 6.x-2.x before 6.x-2.2 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "lists of files." | 2 | 4.3 | Medium | 2017-01-18 | 2013-06-25 | View | |
39175 | CVE-2013-3370 | Request Tracker (RT) 3.8.x before 3.8.17 and 4.0.x before 4.0.13 does not properly restrict access to private callback components, which allows remote attackers to have an unspecified impact via a direct request. | 2 | 6.8 | Medium | 2017-01-18 | 2013-08-26 | View | |
39943 | CVE-2013-4320 | The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.9 and 6.1.x before 6.1.4 does not properly check permissions, which allows remote authenticated users to create or read arbitrary files via a crafted URL. | 2 | 5.5 | Medium | 2017-01-18 | 2014-05-21 | View | |
40199 | CVE-2013-4624 | Multiple cross-site scripting (XSS) vulnerabilities in Jahia xCM 6.6.1.0 before hotfix 7 allow remote attackers to inject arbitrary web script or HTML via (1) the site parameter to engines/manager.jsp, (2) the searchString parameter to administration/ in a search action, or the (3) username, (4) firstName, (5) lastName, (6) email, or (7) organization field to administration/ in a users action. | 2 | 4.3 | Medium | 2017-01-18 | 2013-11-29 | View |
Page 283 of 17672, showing 5 records out of 88360 total, starting on record 1411, ending on 1415