Search Results (Refine Search)
- CPE Product Version: cpe:/a:network-weathermap:.network_weathermap:0.97:a
Vuln ID | Summary | CVSS Severity |
---|---|---|
CVE-2013-3739 |
Directory traversal vulnerability in editor.php in Network Weathermap 0.97c and earlier allows remote attackers to read arbitrary files via a .. (dot dot) in the mapname parameter in a show_config action. Published: June 05, 2014; 4:55:05 PM -0400 |
V4.0:(not available) V3.x:(not available) V2.0: 5.0 MEDIUM |
CVE-2013-2618 |
Cross-site scripting (XSS) vulnerability in editor.php in Network Weathermap before 0.97b allows remote attackers to inject arbitrary web script or HTML via the map_title parameter. Published: June 05, 2014; 4:55:05 PM -0400 |
V4.0:(not available) V3.x:(not available) V2.0: 4.3 MEDIUM |