|
279011
|
2.7 |
LOW
Network
|
phpmyfaq
|
phpmyfaq
|
phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter.
|
CWE-285
Improper Authorization
|
CVE-2014-6049
|
2024-11-21 11:13 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279012
|
5.3 |
MEDIUM
Network
|
phpmyfaq
|
phpmyfaq
|
phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
|
CWE-200
Information Exposure
|
CVE-2014-6048
|
2024-11-21 11:13 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279013
|
5.3 |
MEDIUM
Network
|
phpmyfaq
|
phpmyfaq
|
phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.
|
CWE-275
Permission Issues
|
CVE-2014-6047
|
2024-11-21 11:13 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279014
|
8.8 |
HIGH
Network
|
phpmyfaq
|
phpmyfaq
|
Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication of unspecified users for requests that (1) delete active users…
|
CWE-352
Origin Validation Error
|
CVE-2014-6046
|
2024-11-21 11:13 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279015
|
7.2 |
HIGH
Network
|
phpmyfaq
|
phpmyfaq
|
SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via vectors involving the restore function.
|
CWE-89
SQL Injection
|
CVE-2014-6045
|
2024-11-21 11:13 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279016
|
5.9 |
MEDIUM
Network
|
ibm
|
security_identity_manager tivoli_identity_manager
|
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 make it easier for remote at…
|
CWE-200
Information Exposure
|
CVE-2014-6112
|
2024-11-21 11:13 |
2018-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279017
|
7.8 |
HIGH
Local
|
ibm
|
security_identity_manager tivoli_identity_manager
|
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 store encrypted user credent…
|
CWE-255
Credentials Management
|
CVE-2014-6111
|
2024-11-21 11:13 |
2018-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279018
|
5.3 |
MEDIUM
Network
|
ibm
|
security_identity_manager tivoli_identity_manager
|
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 allow remote authenticated u…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2014-6109
|
2024-11-21 11:13 |
2018-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279019
|
5.9 |
MEDIUM
Network
|
ibm
|
security_identity_manager tivoli_identity_manager
|
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 might allow man-in-the-middl…
|
CWE-200
Information Exposure
|
CVE-2014-6108
|
2024-11-21 11:13 |
2018-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279020
|
5.4 |
MEDIUM
Network
|
ibm
|
forms_experience_builder
|
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.0 and 8.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 97777.
|
CWE-79
Cross-site Scripting
|
CVE-2014-6169
|
2024-11-21 11:13 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|