|
278041
|
- |
|
netfortris
|
trixbox
|
SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL commands via the mac parameter in a Submit action.
|
CWE-89
SQL Injection
|
CVE-2014-5109
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278042
|
- |
|
concrete5 concretecms
|
concrete5 concrete_cms
|
Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to inde…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5108
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278043
|
- |
|
concrete5 concretecms
|
concrete5 concrete_cms
|
concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.php, (3) system/environment/file_storage_locations…
|
CWE-200
Information Exposure
|
CVE-2014-5107
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278044
|
- |
|
invisioncommunity
|
invision_power_board
|
Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.4.x through 3.4.6 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer he…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5106
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278045
|
- |
|
ol-commerce_project
|
ol-commerce
|
Multiple cross-site scripting (XSS) vulnerabilities in ol-commerce 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) a_country parameter in a process action to affiliate…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5105
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278046
|
- |
|
ol-commerce_project
|
ol-commerce
|
Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) a_country parameter in a process action to affiliate_signup.php, (2) a…
|
CWE-89
SQL Injection
|
CVE-2014-5104
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278047
|
- |
|
microsoft
|
windows_xp
|
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a cra…
|
CWE-20
Improper Input Validation
|
CVE-2014-4971
|
2024-11-21 11:11 |
2014-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278048
|
- |
|
apple
|
quicktime
|
Apple QuickTime allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a malformed version number and flags in an mvhd atom.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-4979
|
2024-11-21 11:11 |
2014-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278049
|
- |
|
sabreairlinesolutions
|
crew_management crew_services crew_training crew_operations crew_planning
|
Multiple SQL injection vulnerabilities in CWPLogin.aspx in Sabre AirCentre Crew products 2010.2.12.20008 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) username or (…
|
CWE-89
SQL Injection
|
CVE-2014-4858
|
2024-11-21 11:11 |
2014-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278050
|
- |
|
zohocorp
|
manageengine_eventlog_analyzer
|
Cross-site scripting (XSS) vulnerability in ZOHO ManageEngine EventLog Analyzer 9 build 9000 allows remote attackers to inject arbitrary web script or HTML via the j_username parameter to event/j_sec…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5103
|
2024-11-21 11:11 |
2014-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|