|
277981
|
- |
|
biblio_autocomplete_project
|
biblio_autocomplete
|
SQL injection vulnerability in the "Biblio self autocomplete" submodule in the Biblio Autocomplete module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to execu…
|
CWE-89
SQL Injection
|
CVE-2014-5249
|
2024-11-21 11:11 |
2014-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277982
|
- |
|
mybb
|
mybb
|
Cross-site scripting (XSS) vulnerability in MyBB before 1.6.15 allows remote attackers to inject arbitrary web script or HTML via vectors related to video MyCode.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5248
|
2024-11-21 11:11 |
2014-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277983
|
- |
|
microsoft
|
outlook.com
|
The Microsoft Outlook.com application before 7.8.2.12.49.7090 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sen…
|
CWE-310
Cryptographic Issues
|
CVE-2014-5239
|
2024-11-21 11:11 |
2014-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277984
|
- |
|
openssl
|
openssl
|
The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a Se…
|
NVD-CWE-Other
|
CVE-2014-5139
|
2024-11-21 11:11 |
2014-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277985
|
- |
|
compfight_project
|
compfight
|
Cross-site scripting (XSS) vulnerability in compfight-search.php in the Compfight plugin 1.4 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the search-valu…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5202
|
2024-11-21 11:11 |
2014-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277986
|
- |
|
gallery_objects_project
|
gallery_objects
|
SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the viewid parameter in a go_view_object action to wp-admin/a…
|
CWE-89
SQL Injection
|
CVE-2014-5201
|
2024-11-21 11:11 |
2014-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277987
|
- |
|
fb_gorilla_project
|
fb_gorilla
|
SQL injection vulnerability in game_play.php in the FB Gorilla plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.
|
CWE-89
SQL Injection
|
CVE-2014-5200
|
2024-11-21 11:11 |
2014-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277988
|
- |
|
wordpress_file_upload_project
|
wordpress_file_upload
|
Cross-site request forgery (CSRF) vulnerability in the WordPress File Upload plugin (wp-file-upload) before 2.4.2 for WordPress allows remote attackers to hijack the authentication of administrators …
|
CWE-352
Origin Validation Error
|
CVE-2014-5199
|
2024-11-21 11:11 |
2014-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277989
|
- |
|
splunk
|
splunk
|
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.3 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5198
|
2024-11-21 11:11 |
2014-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277990
|
- |
|
splunk
|
splunk
|
Directory traversal vulnerability in (1) Splunk Web or the (2) Splunkd HTTP Server in Splunk Enterprise 6.1.x before 6.1.3 allows remote authenticated users to read arbitrary files via a .. (dot dot)…
|
CWE-22
Path Traversal
|
CVE-2014-5197
|
2024-11-21 11:11 |
2014-08-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|