CVE Database - 2013

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

1772
Matching CVEs
16133
Critical
35026
High
84348
High WAF Coverage

CVE-2013-6327

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the HTTP Option in IBM Sterling Connect:Enterprise 1.3 before 1.3.0.2 iFix 1 and 1.4 before 1.4.0.0 iFix 1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to a "cross-frame scripting" issue.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-2816

MEDIUM
4.70 CVSS 2.0

The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows physically proximate attackers to cause a denial of service (reboot or link outage) via crafted input over a serial line.

Improper Input Validation
WAF: Medium

CVE-2013-2814

HIGH
7.10 CVSS 2.0

Cooper Power Systems Cybectec DNP3 Master OPC Server allows remote attackers to cause a denial of service (unhandled exception and process crash) via unspecified vectors.

Improper Input Validation
WAF: Medium

CVE-2013-2813

HIGH
7.10 CVSS 2.0

The DNP3 component in Cooper Power Systems SMP 4, 4/DP, and 16 gateways allows remote attackers to cause a denial of service (reboot or link outage) via a crafted DNP3 TCP packet.

Improper Input Validation
WAF: Medium

CVE-2013-6966

MEDIUM
5.80 CVSS 2.0

Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul36031.

Improper Input Validation
WAF: Medium

CVE-2013-6926

HIGH
8.00 CVSS 2.0

The integrated HTTPS server in Siemens RuggedCom ROS before 3.12.2 allows remote authenticated users to bypass intended restrictions on administrative actions by leveraging access to a (1) guest or (2) operator account.

Incorrect Authorization
WAF: Low

CVE-2013-6192

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration before 9 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2013-6191

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in HP Operations Orchestration before 9 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6971

MEDIUM
5.80 CVSS 2.0

Open redirect vulnerability in Cisco WebEx Training Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul57140.

Improper Input Validation
WAF: Medium

CVE-2013-6969

MEDIUM
4.30 CVSS 2.0

The training-registration page in Cisco WebEx Training Center allows remote attackers to modify unspecified fields via unknown vectors, aka Bug ID CSCul35990.

Improper Input Validation
WAF: Medium

CVE-2013-6967

MEDIUM
5.80 CVSS 2.0

Open redirect vulnerability in the mobile-browser subsystem in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul36020.

Improper Input Validation
WAF: Medium

CVE-2013-6963

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the registration component in Cisco WebEx Training Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36207.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6962

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the mobile-browser subsystem in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36228.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6961

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Collaboration Partner Access Console (CPAC) in Cisco WebEx Meeting Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36237.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6960

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in Cisco WebEx Meeting Center allow remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul36248.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6959

MEDIUM
5.80 CVSS 2.0

Open redirect vulnerability in Cisco WebEx Sales Center allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors, aka Bug ID CSCul25557.

Improper Input Validation
WAF: Medium

CVE-2013-6711

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the product-creation administrative page in Cisco WebEx Sales Center allows remote attackers to inject arbitrary web script or HTML via a crafted URL, aka Bug ID CSCul25540.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6710

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Training Center allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, aka Bug ID CSCul25567.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2013-5438

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the web server in IBM Flex System Manager (FSM) 1.1.0 through 1.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-4845

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability on HP Officejet Pro 8500 (aka A909) All-in-One printers allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-4001

MEDIUM
4.30 CVSS 2.0

Session fixation vulnerability in IBM Cognos Command Center before 10.2 allows remote attackers to hijack web sessions via an authorization cookie.

Improper Authentication
WAF: Low

CVE-2013-4000

MEDIUM
6.80 CVSS 2.0

Multiple cross-site request forgery (CSRF) vulnerabilities in IBM Cognos Command Center before 10.2 allow remote attackers to hijack the authentication of administrators for requests that (1) start or (2) stop services.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2013-3043

LOW
2.10 CVSS 2.0

Directory traversal vulnerability in the client in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.

Path Traversal
WAF: High

CVE-2013-3042

LOW
2.10 CVSS 2.0

Directory traversal vulnerability in the server in IBM Rational Software Architect Design Manager and Rhapsody Design Manager 3.x and 4.x before 4.0.5 allows local users to read arbitrary files via vectors involving temporary files.

Path Traversal
WAF: High

CVE-2013-6368

MEDIUM
6.20 CVSS 2.0

The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address.

Improper Input Validation
WAF: Medium

CVE-2013-4587

HIGH
7.20 CVSS 2.0

Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value.

Improper Input Validation
WAF: Medium

CVE-2013-7104

HIGH
9.00 CVSS 2.0

McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands by specifying them in the value attribute in a (1) Command or (2) Script XML element. NOTE: this issue can be combined with CVE-2013-7092 to allow remote attackers to execute commands.

OS Command Injection
WAF: High

CVE-2013-7103

HIGH
9.00 CVSS 2.0

McAfee Email Gateway 7.6 allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the value attribute in a (1) TestFile XML element or the (2) hostname. NOTE: this issue can be combined with CVE-2013-7092 to allow remote attackers to execute commands.

OS Command Injection
WAF: High

CVE-2013-7085

MEDIUM
5.80 CVSS 2.0

Uscan in devscripts 2.13.5, when USCAN_EXCLUSION is enabled, allows remote attackers to delete arbitrary files via a whitespace character in a filename.

Improper Input Validation
WAF: Medium

CVE-2013-7069

MEDIUM
6.80 CVSS 2.0

ack 2.00 through 2.11_02 allows remote attackers to execute arbitrary code via a (1) --pager, (2) --regex, or (3) --output option in a .ackrc file in a directory to be searched.

Code Injection
WAF: Medium

CVE-2013-6391

MEDIUM
5.80 CVSS 2.0

The ec2tokens API in OpenStack Identity (Keystone) before Havana 2013.2.1 and Icehouse before icehouse-2 does not return a trust-scoped token when one is received, which allows remote trust users to gain privileges by generating EC2 credentials from a trust-scoped token and using them in an ec2tokens API request.

Improper Privilege Management
WAF: Low

CVE-2013-5107

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in RockMongo 1.1.5 and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the ROCK_LANG cookie, as demonstrated in a login.index action to index.php.

Path Traversal
WAF: High

CVE-2013-1364

MEDIUM
5.00 CVSS 2.0

The user.login function in Zabbix before 1.8.16 and 2.x before 2.0.5rc1 allows remote attackers to override LDAP configuration via the cnf parameter.

Improper Authentication
WAF: Low

CVE-2013-7096

HIGH
7.50 CVSS 2.0

Multiple SQL injection vulnerabilities in SAP EMR Unwired allow remote attackers to execute arbitrary SQL commands via unspecified vectors.

SQL Injection
WAF: High

CVE-2013-7094

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in the RSDDCVER_COUNT_TAB_COLS function in SAP NetWeaver 7.30 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

SQL Injection
WAF: High

CVE-2013-7093

MEDIUM
5.00 CVSS 2.0

SAP Network Interface Router (SAProuter) 39.3 SP4 allows remote attackers to bypass authentication and modify the configuration via unspecified vectors.

Improper Authentication
WAF: Low

CVE-2013-6359

MEDIUM
4.30 CVSS 2.0

Munin::Master::Node in Munin before 2.0.18 allows remote attackers to cause a denial of service (abort data collection for node) via a plugin that uses "multigraph" as a multigraph service name.

Improper Input Validation
WAF: Medium

CVE-2013-6048

MEDIUM
5.00 CVSS 2.0

The get_group_tree function in lib/Munin/Master/HTMLConfig.pm in Munin before 2.0.18 allows remote nodes to cause a denial of service (infinite loop and memory consumption in the munin-html process) via crafted multigraph data.

Improper Input Validation
WAF: Medium

CVE-2013-7092

MEDIUM
6.50 CVSS 2.0

Multiple SQL injection vulnerabilities in /admin/cgi-bin/rpc/doReport/18 in McAfee Email Gateway 7.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) events_col, (2) event_id, (3) reason, (4) events_order, (5) emailstatus_order, or (6) emailstatus_col JSON keys.

SQL Injection
WAF: High

CVE-2013-7091

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in /res/I18nMsg,AjxMsg,ZMsg,ZmMsg,AjxKeys,ZmKeys,ZdMsg,Ajx%20TemplateMsg.js.zgz in Zimbra 7.2.2 and 8.0.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the skin parameter. NOTE: this can be leveraged to execute arbitrary code by obtaining LDAP credentials and accessing the service/admin/soap API.

Path Traversal
WAF: High

CVE-2013-7050

MEDIUM
6.80 CVSS 2.0

The get_main_source_dir function in scripts/uscan.pl in devscripts before 2.13.8, when using USCAN_EXCLUSION, allows remote attackers to execute arbitrary commands via shell metacharacters in a directory name.

Code Injection
WAF: Medium

CVE-2013-6957

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the web administrative component in Juniper IDP allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to the ACM web server.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6956

LOW
2.10 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the Secure Access Service Web rewriting feature in Juniper Junos Pulse Secure Access Service (aka SSL VPN) with IVE OS before 7.1r17, 7.3 before 7.3r8, 7.4 before 7.4r6, and 8.0 before 8.0r1, when web rewrite is enabled, allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2012-5394

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in the CentralAuth extension for MediaWiki before 1.19.9, 1.20.x before 1.20.8, and 1.21.x before 1.21.3 allows remote attackers to hijack the authentication of users for requests that login via vectors involving image loading.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2013-6839

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in InstantSoft InstantCMS 1.10.3 and earlier allows remote attackers to execute arbitrary SQL commands via the orderby parameter to catalog/[id].

SQL Injection
WAF: High

CVE-2013-6005

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Cybozu Dezie before 8.1.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to the Cancel button.

Cross-Site Scripting (XSS)
WAF: High

CVE-2013-6421

HIGH
7.50 CVSS 2.0

The unpack_zip function in archive_unpacker.rb in the sprout gem 0.7.246 for Ruby allows context-dependent attackers to execute arbitrary commands via shell metacharacters in a (1) filename or (2) path.

Code Injection
WAF: Medium

CVE-2013-2752

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in frontview/lib/np_handler.pl in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attackers to hijack the authentication of users.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2013-2751

HIGH
10.00 CVSS 2.0

Eval injection vulnerability in frontview/lib/np_handler.pl in the FrontView web interface in NETGEAR ReadyNAS RAIDiator before 4.1.12 and 4.2.x before 4.2.24 allows remote attackers to execute arbitrary Perl code via a crafted request, related to the "forgot password workflow."

Code Injection
WAF: Medium

CVE-2013-6810

HIGH
10.00 CVSS 2.0

The server in Brocade Network Advisor before 12.1.0, as used in EMC Connectrix Manager Converged Network Edition (CMCNE), HP B-series SAN Network Advisor, and possibly other products, allows remote attackers to execute arbitrary code by using a servlet to upload an executable file.

Code Injection
WAF: Medium
Page 3 of 36 (1772 CVEs)