Show filters
2 Total Results
Displaying 1-2 of 2
Sort by:
Attacker Value
Unknown

CVE-2013-3709

Disclosure Date: December 23, 2013 (last updated October 05, 2023)
WebYaST 1.3 uses weak permissions for config/initializers/secret_token.rb, which allows local users to gain privileges by reading the Rails secret token from this file.
0
Attacker Value
Unknown

CVE-2013-4547

Disclosure Date: November 23, 2013 (last updated October 05, 2023)
nginx 0.8.41 through 1.4.3 and 1.5.x before 1.5.7 allows remote attackers to bypass intended restrictions via an unescaped space character in a URI.
0