|
281061
|
- |
|
siemens
|
simatic_s7-1500_cpu_firmware
|
Cross-site request forgery (CSRF) vulnerability on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 and SIMATIC S7-1200 CPU PLC devices with firmware before 4.0 allows remote attack…
|
CWE-352
Origin Validation Error
|
CVE-2014-2249
|
2024-11-21 11:05 |
2014-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281062
|
- |
|
siemens
|
simatic_s7-1500_cpu_firmware
|
Open redirect vulnerability in the integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to redirect users to arbitrary web sites and con…
|
NVD-CWE-Other
|
CVE-2014-2248
|
2024-11-21 11:05 |
2014-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281063
|
- |
|
siemens
|
simatic_s7-1500_cpu_firmware
|
The integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to inject headers via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2014-2247
|
2024-11-21 11:05 |
2014-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281064
|
- |
|
siemens
|
simatic_s7-1500_cpu_firmware
|
Cross-site scripting (XSS) vulnerability in the integrated web server on Siemens SIMATIC S7-1500 CPU PLC devices with firmware before 1.5.0 allows remote attackers to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2246
|
2024-11-21 11:05 |
2014-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281065
|
- |
|
owncloud
|
owncloud
|
The default Flash Cross Domain policies in ownCloud before 5.0.15 and 6.x before 6.0.2 allows remote attackers to access user files via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2049
|
2024-11-21 11:05 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281066
|
- |
|
owncloud
|
owncloud
|
Session fixation vulnerability in ownCloud before 6.0.2, when PHP is configured to accept session parameters through a GET request, allows remote attackers to hijack web sessions via unspecified vect…
|
CWE-287
Improper Authentication
|
CVE-2014-2047
|
2024-11-21 11:05 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281067
|
- |
|
file_project php debian canonical opensuse
|
file php debian_linux ubuntu_linux opensuse
|
softmagic.c in file before 5.17 and libmagic allows context-dependent attackers to cause a denial of service (out-of-bounds memory access and crash) via crafted offsets in the softmagic of a PE execu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-2270
|
2024-11-21 11:05 |
2014-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281068
|
- |
|
openclassifieds
|
open_classifieds_2
|
Cross-site scripting (XSS) vulnerability in classes/controller/error.php in Open Classifieds 2 before 2.1.3 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to shared-…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2024
|
2024-11-21 11:05 |
2014-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281069
|
- |
|
rocklobster
|
contact_form_7
|
Rock Lobster Contact Form 7 before 3.7.2 allows remote attackers to bypass the CAPTCHA protection mechanism and submit arbitrary form data by omitting the _wpcf7_captcha_challenge_captcha-719 paramet…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2265
|
2024-11-21 11:05 |
2014-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281070
|
- |
|
procentia
|
intellipen
|
SQL injection vulnerability in Resources/System/Templates/Data.aspx in Procentia IntelliPen before 1.1.18.1658 allows remote authenticated users to execute arbitrary SQL commands via the value parame…
|
CWE-89
SQL Injection
|
CVE-2014-2043
|
2024-11-21 11:05 |
2014-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|