|
278081
|
- |
|
shopizer
|
shopizer
|
Shopizer 1.1.5 and earlier allows remote attackers to modify the account settings of arbitrary users via the customer.customerId parameter to shop/profile/register.action.
|
NVD-CWE-noinfo
|
CVE-2014-4963
|
2024-11-21 11:11 |
2014-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278082
|
- |
|
shopizer
|
shopizer
|
Shopizer 1.1.5 and earlier allows remote attackers to reduce the total cost of their shopping cart via a negative number in the productQuantity parameter, which causes the price of the item to be sub…
|
CWE-189
Numeric Errors
|
CVE-2014-4962
|
2024-11-21 11:11 |
2014-07-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278083
|
- |
|
horde
|
internet_mail_program groupware
|
Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5, allow remote attackers to inject arbitr…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4946
|
2024-11-21 11:11 |
2014-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278084
|
- |
|
horde
|
internet_mail_program groupware
|
Multiple cross-site scripting (XSS) vulnerabilities in Horde Internet Mail Program (IMP) before 6.1.8, as used in Horde Groupware Webmail Edition before 5.1.5, allow remote attackers to inject arbitr…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4945
|
2024-11-21 11:11 |
2014-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278085
|
- |
|
bannersky
|
bsk_pdf_manager
|
Multiple SQL injection vulnerabilities in inc/bsk-pdf-dashboard.php in the BSK PDF Manager plugin 1.3.2 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) ca…
|
CWE-89
SQL Injection
|
CVE-2014-4944
|
2024-11-21 11:11 |
2014-07-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278086
|
- |
|
levelfourdevelopment
|
wp-easycart
|
The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls the phpinfo functio…
|
CWE-200
Information Exposure
|
CVE-2014-4942
|
2024-11-21 11:11 |
2014-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278087
|
- |
|
cross-rss_plugin_project
|
wp-cross-rss
|
Absolute path traversal vulnerability in Cross-RSS (wp-cross-rss) plugin 1.7 for WordPress allows remote attackers to read arbitrary files via a full pathname in the rss parameter to proxy.php.
|
CWE-22
Path Traversal
|
CVE-2014-4941
|
2024-11-21 11:11 |
2014-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278088
|
- |
|
tera_charts_plugin_project
|
tera-charts
|
Multiple directory traversal vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/…
|
CWE-22
Path Traversal
|
CVE-2014-4940
|
2024-11-21 11:11 |
2014-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278089
|
- |
|
enl_newsletter_plugin_project
|
enl-newsletter
|
SQL injection vulnerability in the ENL Newsletter (enl-newsletter) plugin 1.0.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the …
|
CWE-89
SQL Injection
|
CVE-2014-4939
|
2024-11-21 11:11 |
2014-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278090
|
- |
|
wp_rss_poster_plugin_project
|
wp-rss-poster
|
SQL injection vulnerability in the WP Rss Poster (wp-rss-poster) plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter in the wrp-add-new page to w…
|
CWE-89
SQL Injection
|
CVE-2014-4938
|
2024-11-21 11:11 |
2014-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|