|
280801
|
- |
|
cmsmadesimple
|
cms_made_simple
|
Cross-site scripting (XSS) vulnerability in lib/filemanager/ImageManager/editorFrame.php in CMS Made Simple 1.11.10 allows remote attackers to inject arbitrary web script or HTML via the action param…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2092
|
2024-11-21 11:05 |
2014-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280802
|
- |
|
atutor
|
atutor
|
Cross-site scripting (XSS) vulnerability in mods/_standard/forums/admin/forum_add.php in ATutor 2.1.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the title p…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2091
|
2024-11-21 11:05 |
2014-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280803
|
- |
|
ilias
|
ilias
|
Multiple cross-site scripting (XSS) vulnerabilities in ilias.php in ILIAS 4.4.1 allow remote authenticated users to inject arbitrary web script or HTML via the (1) tar, (2) tar_val, or (3) title para…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2090
|
2024-11-21 11:05 |
2014-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280804
|
- |
|
ilias
|
ilias
|
ILIAS 4.4.1 allows remote attackers to execute arbitrary PHP code via an e-mail attachment that leads to creation of a .php file with a certain client_id pathname.
|
CWE-94
Code Injection
|
CVE-2014-2089
|
2024-11-21 11:05 |
2014-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280805
|
- |
|
ilias
|
ilias
|
Unrestricted file upload vulnerability in ilias.php in ILIAS 4.4.1 allows remote authenticated users to execute arbitrary PHP code by using a .php filename in an upload_files action to the uploadFile…
|
NVD-CWE-Other
|
CVE-2014-2088
|
2024-11-21 11:05 |
2014-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280806
|
- |
|
bluecoat
|
proxysgos
|
The caching feature in SGOS in Blue Coat ProxySG 5.5 through 5.5.11.3, 6.1 through 6.1.6.3, 6.2 through 6.2.15.3, 6.4 through 6.4.6.1, and 6.3 and 6.5 before 6.5.4 allows remote authenticated users t…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-2033
|
2024-11-21 11:05 |
2014-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280807
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in the formatHTML function in includes/api/ApiFormatBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 allows rem…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2244
|
2024-11-21 11:05 |
2014-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280808
|
- |
|
mediawiki
|
mediawiki
|
includes/User.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 terminates validation of a user token upon encountering the first incorrect character, which m…
|
CWE-362
Race Condition
|
CVE-2014-2243
|
2024-11-21 11:05 |
2014-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280809
|
- |
|
mediawiki
|
mediawiki
|
includes/upload/UploadBase.php in MediaWiki before 1.19.12, 1.20.x and 1.21.x before 1.21.6, and 1.22.x before 1.22.3 does not prevent use of invalid namespaces in SVG files, which allows remote atta…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2242
|
2024-11-21 11:05 |
2014-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280810
|
- |
|
cisco
|
unified_communications_domain_manager
|
Multiple cross-site scripting (XSS) vulnerabilities in the Business Voice Services Manager (BVSM) page in Cisco Unified Communications Domain Manager 9.0(.1) allow remote attackers to inject arbitrar…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2104
|
2024-11-21 11:05 |
2014-03-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|