Show filters
469 Total Results
Displaying 391-400 of 469
Sort by:
Attacker Value
Unknown

CVE-2013-6310

Disclosure Date: June 28, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2013-6308

Disclosure Date: June 28, 2014 (last updated October 05, 2023)
IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to conduct phishing attacks and capture login credentials via an unspecified injection.
0
Attacker Value
Unknown

CVE-2013-6309

Disclosure Date: June 28, 2014 (last updated October 05, 2023)
IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to hijack sessions, and consequently read records, modify records, or conduct transactions, via an unspecified link injection.
0
Attacker Value
Unknown

CVE-2013-6311

Disclosure Date: June 28, 2014 (last updated October 05, 2023)
SQL injection vulnerability in IBM Marketing Platform 9.1 before FP2 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
0
Attacker Value
Unknown

CVE-2014-2846

Disclosure Date: April 28, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in opt/arkeia/wui/htdocs/index.php in the WD Arkeia virtual appliance (AVA) with firmware before 10.2.9 allows remote attackers to read arbitrary files and execute arbitrary PHP code via a ..././ (dot dot dot slash dot slash) in the lang Cookie parameter, as demonstrated by a request to login/doLogin.
0
Attacker Value
Unknown

CVE-2013-3263

Disclosure Date: November 05, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress allow remote attackers to inject arbitrary web script or HTML via the (1) siteurl parameter to campaign/campaignone.php; the (2) action, (3) campaignname, (4) campaignformat, or (5) emailtemplate parameter to campaign/campaigntwo.php; the (6) listid parameter to list/edit.php; the (7) campaignid or (8) siteurl parameter to campaign/editcampaign.php; the (9) campaignid parameter to campaign/selectlistb4send.php; the (10) campaignid, (11) campaignname, (12) campaignsubject, or (13) selectedcampaigns parameter to campaign/sendCampaign.php; or the (14) campaignid, (15) campaignname, (16) campaignformat, or (17) action parameter to campaign/updatecampaign.php.
0
Attacker Value
Unknown

CVE-2013-3264

Disclosure Date: November 05, 2013 (last updated October 05, 2023)
The WP Ultimate Email Marketer plugin 1.1.0 and possibly earlier for Wordpress does not properly restrict access to (1) list/edit.php and (2) campaign/editCampaign.php, which allows remote attackers to modify list or campaign data.
0
Attacker Value
Unknown

CVE-2013-3285

Disclosure Date: November 02, 2013 (last updated October 05, 2023)
The NetWorker Management Console (NMC) in EMC NetWorker 8.0.x before 8.0.2.3, when using Active Directory/LDAP for authentication, allows remote authenticated users to discover cleartext administrator passwords via (1) unspecified NMC audit reports or (2) requests to RAP resources.
0
Attacker Value
Unknown

CVE-2013-0943

Disclosure Date: July 31, 2013 (last updated October 05, 2023)
EMC NetWorker 7.6.x and 8.x before 8.1 allows local users to obtain sensitive configuration information by leveraging operating-system privileges to perform decryption with nsradmin.
0
Attacker Value
Unknown

CVE-2013-0940

Disclosure Date: May 03, 2013 (last updated October 05, 2023)
The nsrpush process in the client in EMC NetWorker before 7.6.5.3 and 8.x before 8.0.1.4 sets weak permissions for unspecified files, which allows local users to gain privileges via unknown vectors.
0