CVE Database - 2013

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

1772
Matching CVEs
16133
Critical
35026
High
84348
High WAF Coverage

CVE-2013-3667

MEDIUM
6.40 CVSS 2.0

The software update mechanism as used in Bare Bones Software Yojimbo before 4.0, TextWrangler before 4.5.3, and BBEdit before 10.5.5 does not properly download and verify updates before installation, which allows attackers to perform "tampering or corruption" of the updates.

Improper Input Validation
WAF: Medium

CVE-2013-3572

MEDIUM
6.10 CVSS 3.1

Cross-site scripting (XSS) vulnerability in the administer interface in the UniFi Controller in Ubiquiti Networks UniFi 2.3.5 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted client hostname.

Cross-Site Scripting (XSS)
WAF: High

CVE-2012-0262

HIGH
10.00 CVSS 2.0

op5config/welcome in system-op5config before 2.0.3 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the password parameter.

Code Injection
WAF: Medium

CVE-2012-0261

HIGH
10.00 CVSS 2.0

license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the timestamp parameter for an install action.

Code Injection
WAF: Medium

CVE-2013-6987

HIGH
7.50 CVSS 2.0

Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remote attackers to read, write, and delete arbitrary files via a .. (dot dot) in the (1) path parameter to file_delete.cgi or (2) folder_path parameter to file_share.cgi in webapi/FileStation/; (3) dlink parameter to fbdownload/; or unspecified parameters to (4) html5_upload.cgi, (5) file_download.cgi, (6) file_sharing.cgi, (7) file_MVCP.cgi, or (8) file_rename.cgi in webapi/FileStation/.

Path Traversal
WAF: High

CVE-2013-6459

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the will_paginate gem before 3.0.5 for Ruby allows remote attackers to inject arbitrary web script or HTML via vectors involving generated pagination links.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-5573

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the default markup formatter in Jenkins 1.523 allows remote attackers to inject arbitrary web script or HTML via the Description field in the user configuration.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-7242

MEDIUM
6.50 CVSS 2.0

SQL injection vulnerability in zp-core/zp-extensions/wordpress_import.php in Zenphoto before 1.4.5.4 allows remote authenticated administrators to execute arbitrary SQL commands via the tableprefix parameter.

SQL Injection
WAF: High

CVE-2013-7241

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the export function in zp-core/zp-extensions/mergedRSS.php in Zenphoto before 1.4.5.4 allows remote attackers to inject arbitrary web script or HTML via the URI.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6983

MEDIUM
6.50 CVSS 2.0

SQL injection vulnerability in the web interface in Cisco Unified Presence Server allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuh35615.

SQL Injection
WAF: High

CVE-2013-7209

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in admBase/login.page in the Admin module in JForum allows remote attackers to hijack the authentication of administrators for requests that change the user group permissions of arbitrary users via a groupsSave action.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2013-7233

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in the retrospam component in wp-admin/options-discussion.php in WordPress 2.0.11 and earlier allows remote attackers to hijack the authentication of administrators for requests that move comments to the moderation list.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2013-7232

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in ESRI ArcGIS for Server through 10.2 allows remote attackers to execute arbitrary SQL commands via unspecified input to the map or feature service.

SQL Injection
WAF: High

CVE-2013-7231

LOW
3.50 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Mobile Content Server in ESRI ArcGIS for Server 10.1 and 10.2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2013-5222.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-5222

LOW
3.50 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in ESRI ArcGIS for Server 10.1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-5220

MEDIUM
6.10 CVSS 2.0

goform/login on the HOT HOTBOX router with software 2.1.11 allows remote attackers to cause a denial of service (device crash) via crafted HTTP POST data.

Improper Input Validation
WAF: Medium

CVE-2013-5219

LOW
3.30 CVSS 2.0

Directory traversal vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to read arbitrary files via a .. (dot dot) in a URI, as demonstrated by a request for /etc/passwd.

Path Traversal
WAF: High

CVE-2013-5218

LOW
2.90 CVSS 2.0

Cross-site scripting (XSS) vulnerability on the HOT HOTBOX router with software 2.1.11 allows remote attackers to inject arbitrary web script or HTML via a crafted DHCP Host Name option, which is not properly handled during rendering of the DHCP table in wlanAccess.asp.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-5210

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the GUI login page in ADTRAN AOS before R10.8.1 on the NetVanta 7100 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-5039

MEDIUM
5.40 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in goform/wlanBasicSecurity on the HOT HOTBOX router with software 2.1.11 allows remote attackers to hijack the authentication of administrators for requests that change the WiFi Security field to Deactivated via the WifiSecurity parameter.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2013-5038

MEDIUM
5.80 CVSS 2.0

The HOT HOTBOX router with software 2.1.11 allows remote attackers to bypass authentication by configuring a source IP address that had previously been used for an authenticated session.

Improper Authentication
WAF: Low

CVE-2013-4858

MEDIUM
4.30 CVSS 2.0

Microsoft Windows Movie Maker 2.1.4026.0 on Windows XP SP3 allows remote attackers to cause a denial of service (application crash) via a crafted .wav file, as demonstrated by movieMaker.wav.

Improper Input Validation
WAF: Medium

CVE-2013-6198

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in HP Service Manager WebTier and Windows Client 9.20 and 9.21 before 9.21.661 p8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-5583

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in libraries/idna_convert/example.php in Joomla! 3.1.5 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-2504

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in SPS/Portal/default.aspx in Service Desk in Matrix42 Service Store 5.3 SP3 (aka 5.33.946.0) allows remote attackers to inject arbitrary web script or HTML via the query string.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-7149

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in www/delivery/axmlrpc.php (aka the XML-RPC delivery invocation script) in Revive Adserver before 3.0.2, and OpenX Source 2.8.11 and earlier, allows remote attackers to execute arbitrary SQL commands via the what parameter to an XML-RPC method.

SQL Injection
WAF: High

CVE-2013-6981

MEDIUM
5.40 CVSS 2.0

Cisco IOS XE 3.7S(.1) and earlier allows remote attackers to cause a denial of service (Packet Processor crash) via fragmented MPLS IP packets, aka Bug ID CSCul00709.

Improper Input Validation
WAF: Medium

CVE-2013-6929

MEDIUM
6.50 CVSS 2.0

SQL injection vulnerability in Cybozu Garoon 3.7 SP2 and earlier allows remote authenticated users to execute arbitrary SQL commands via crafted API input.

SQL Injection
WAF: High

CVE-2013-6808

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in lib/NSSDropoff.php in ZendTo before 4.11-13 allows remote attackers to inject arbitrary web script or HTML via a modified emailAddr field to pickup.php.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6006

MEDIUM
5.80 CVSS 2.0

Cybozu Garoon 3.5 through 3.7 SP2 allows remote attackers to bypass Keitai authentication via a modified user ID in a request.

Improper Authentication
WAF: Low

CVE-2013-1096

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Roles Based Provisioning Module 4.0.2 before Field Patch D for Novell Identity Manager (aka IDM) allows remote attackers to inject arbitrary web script or HTML via a taskDetail taskId.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-7216

HIGH
7.50 CVSS 2.0

Multiple SQL injection vulnerabilities in Classifieds Creator 2.0 allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to demo/classifieds/product.asp, or (2) UserID or (3) Password field to demo/classifieds/admin.asp.

SQL Injection
WAF: High

CVE-2013-6388

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Color module in Drupal 7.x before 7.24 allows remote attackers to inject arbitrary web script or HTML via vectors related to CSS.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6387

LOW
2.10 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Image module in Drupal 7.x before 7.24 allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via the description field.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6795

HIGH
9.30 CVSS 2.0

The Updater in Rackspace Openstack Windows Guest Agent for XenServer before 1.2.6.0 allows remote attackers to execute arbitrary code via a crafted serialized .NET object to TCP port 1984, which triggers the download and extraction of a ZIP file that overwrites the Agent service binary.

Code Injection
WAF: Medium

CVE-2013-7102

MEDIUM
6.80 CVSS 2.0

Multiple unrestricted file upload vulnerabilities in (1) media-upload.php, (2) media-upload-lncthumb.php, and (3) media-upload-sq_button.php in lib/admin/ in the OptimizePress theme before 1.61 for WordPress allow remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images_comingsoon, images_lncthumbs, or images_optbuttons in wp-content/uploads/optpress/, as exploited in the wild in November 2013.

Improper Input Validation
WAF: Medium

CVE-2013-7079

MEDIUM
5.80 CVSS 2.0

Open redirect vulnerability in the OpenID extension in TYPO3 4.5.0 through 4.5.31, 4.7.0 through 4.7.16, 6.0.0 through 6.0.11, and 6.1.0 through 6.1.6 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

Improper Input Validation
WAF: Medium

CVE-2013-4424

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in the GateIn Portal component in Red Hat JBoss Portal 6.1.0 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6979

MEDIUM
5.40 CVSS 2.0

The VTY authentication implementation in Cisco IOS XE 03.02.xxSE and 03.03.xxSE incorrectly relies on the Linux-IOS internal-network configuration, which allows remote attackers to bypass authentication by leveraging access to a 192.168.x.2 source IP address, aka Bug ID CSCuj90227.

Improper Authentication
WAF: Low

CVE-2013-6890

MEDIUM
5.00 CVSS 2.0

denyhosts 2.6 uses an incorrect regular expression when analyzing authentication logs, which allows remote attackers to cause a denial of service (incorrect block of IP addresses) via crafted login names.

Improper Authentication
WAF: Low

CVE-2013-6439

HIGH
9.30 CVSS 2.0

Candlepin in Red Hat Subscription Asset Manager 1.0 through 1.3 uses a weak authentication scheme when the configuration file does not specify a scheme, which has unspecified impact and attack vectors.

Improper Authentication
WAF: Low

CVE-2013-6422

MEDIUM
4.00 CVSS 2.0

The GnuTLS backend in libcurl 7.21.4 through 7.33.0, when disabling digital signature verification (CURLOPT_SSL_VERIFYPEER), also disables the CURLOPT_SSL_VERIFYHOST check for CN or SAN host name fields, which makes it easier for remote attackers to spoof servers and conduct man-in-the-middle (MITM) attacks.

Improper Input Validation
WAF: Medium

CVE-2013-4549

MEDIUM
5.00 CVSS 2.0

QXmlSimpleReader in Qt before 5.2 allows context-dependent attackers to cause a denial of service (memory consumption) via an XML Entity Expansion (XEE) attack.

Improper Input Validation
WAF: Medium

CVE-2013-4461

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to execute arbitrary SQL commands via vectors related to the "filtering table operator."

SQL Injection
WAF: High

CVE-2013-4414

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allows remote attackers to inject arbitrary web script or HTML via the "Max allowance" field in the "Set limit" form.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-4405

MEDIUM
6.80 CVSS 2.0

Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface for cumin in Red Hat Enterprise MRG Grid 2.4 allow remote attackers to hijack the authentication of cumin users for unspecified requests.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2013-2629

MEDIUM
5.00 CVSS 2.0

Leed (Light Feed), possibly before 1.5 Stable, allows remote attackers to bypass authorization via vectors related to the (1) importForm, (2) importFeed, (3) addFavorite, or (4) removeFavorite actions in action.php.

Improper Input Validation
WAF: Medium

CVE-2013-6745

LOW
3.50 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote authenticated users to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6328

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Web Content Manager (WCM) UI in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.0.0.x through 7.0.0.2 CF26, and 8.0.0.x before 8.0.0.1 CF09 allows remote attackers to inject arbitrary web script or HTML via vectors involving IFRAME elements.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-5421

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the IMS server before Ifix 6 in IBM Security Access Manager for Enterprise Single Sign-On (ISAM ESSO) 8.2 allows remote attackers to inject arbitrary web script or HTML via crafted input to an unspecified dynamic web form.

Cross-Site Scripting (XSS)
WAF: High
Page 1 of 36 (1772 CVEs)