NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
37896 | CVE-2013-1734 | Cross-site request forgery (CSRF) vulnerability in attachment.cgi in Bugzilla 2.x, 3.x, and 4.0.x before 4.0.11; 4.1.x and 4.2.x before 4.2.7; and 4.3.x and 4.4.x before 4.4.1 allows remote attackers to hijack the authentication of arbitrary users for requests that commit an attachment change via an update action. | 2 | 6.8 | Medium | 2017-01-18 | 2013-10-24 | View | |
39176 | CVE-2013-3371 | Cross-site scripting (XSS) vulnerability in Request Tracker (RT) 3.8.3 through 3.8.16 and 4.0.x before 4.0.13 allows remote attackers to inject arbitrary web script or HTML via the filename of an attachment. | 2 | 4.3 | Medium | 2017-01-18 | 2013-08-26 | View | |
39688 | CVE-2013-3996 | IBM InfoSphere BigInsights 1.1 through 2.1 does not properly handle FRAME elements, which makes it easier for remote authenticated users to conduct phishing attacks via a crafted web site. | 2 | 4.9 | Medium | 2017-01-18 | 2013-08-22 | View | |
39944 | CVE-2013-4321 | The File Abstraction Layer (FAL) in TYPO3 6.0.x before 6.0.8 and 6.1.x before 6.1.4 allows remote authenticated editors to execute arbitrary PHP code via unspecified characters in the file extension when renaming a file. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-4250. | 2 | 6.5 | Medium | 2017-01-18 | 2014-05-21 | View | |
40200 | CVE-2013-4625 | Cross-site scripting (XSS) vulnerability in files/installer.cleanup.php in the Duplicator plugin before 0.4.5 for WordPress allows remote attackers to inject arbitrary web script or HTML via the package parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2013-10-07 | View |
Page 319 of 17672, showing 5 records out of 88360 total, starting on record 1591, ending on 1595