|
276871
|
- |
|
xornic
|
contact_us
|
Multiple cross-site scripting (XSS) vulnerabilities in Xornic Contact Us allow remote attackers to inject arbitrary web script or HTML via the (1) name or (2) email parameter to contact.php or (3) PA…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8365
|
2024-11-21 11:18 |
2014-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276872
|
- |
|
tim_rohrer
|
wordpress_spreadsheet_plugin
|
Cross-site scripting (XSS) vulnerability in ss_handler.php in the WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress allows remote attackers to inject arbitrary web script or HTML via the ss_id p…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8364
|
2024-11-21 11:18 |
2014-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276873
|
- |
|
wordpress_spreadsheet_project
|
wordpress_spreadsheet
|
SQL injection vulnerability in ss_handler.php in the WordPress Spreadsheet (wpSS) plugin 0.62 for WordPress allows remote attackers to execute arbitrary SQL commands via the ss_id parameter.
|
CWE-89
SQL Injection
|
CVE-2014-8363
|
2024-11-21 11:18 |
2014-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276874
|
- |
|
huawei
|
e3276_firmware e3236_firmware
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3236 before E3276sTCPU-V200R002B470D13SP00C00 and E3276sWebUI-V100R007B100D03SP01C03 and E3276 before E3236sTCPU-V200R002B…
|
CWE-352
Origin Validation Error
|
CVE-2014-8331
|
2024-11-21 11:18 |
2014-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276875
|
- |
|
espocrm
|
espocrm
|
Cross-site scripting (XSS) vulnerability in EspoCRM allows remote authenticated users to inject arbitrary web script or HTML via the Name field in a new account.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8330
|
2024-11-21 11:18 |
2014-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276876
|
- |
|
schrack
|
technik_microcontrol_firmware technik_microcontrol
|
Schrack Technik microControl with firmware before 1.7.0 (937) stores sensitive information under the web root with insufficient access control, which allows remote attackers to obtain access data for…
|
CWE-287
Improper Authentication
|
CVE-2014-8329
|
2024-11-21 11:18 |
2014-10-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276877
|
- |
|
-
|
-
|
Cross-site request forgery (CSRF) vulnerability in HP System Management Homepage (SMH) before 3.2.3 on HP-UX B.11.23, and before 3.2.8 on HP-UX B.11.31, allows remote attackers to hijack the authenti…
|
CWE-352
Origin Validation Error
|
CVE-2014-7874
|
2024-11-21 11:18 |
2014-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276878
|
- |
|
foxitsoftware
|
foxit_pdf_sdk_activex
|
Buffer overflow in the SetLogFile method in Foxit.FoxitPDFSDKProCtrl.5 in Foxit PDF SDK ActiveX 2.3 through 5.0.1820 before 5.0.2.924 allows remote attackers to execute arbitrary code via a long stri…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-8074
|
2024-11-21 11:18 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276879
|
- |
|
openstack
|
swift
|
OpenStack Object Storage (Swift) before 2.2.0 allows remote authenticated users to bypass the max_meta_count and other metadata constraints via multiple crafted requests which exceed the limit when c…
|
CWE-399
Resource Management Errors
|
CVE-2014-7960
|
2024-11-21 11:18 |
2014-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276880
|
- |
|
custom_search_project
|
custom_search
|
Cross-site scripting (XSS) vulnerability in the Custom Search module 6.x-1.x before 6.x-1.12 and 7.x-1.x before 7.x-1.14 for Drupal allows remote authenticated users with certain permissions to injec…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8320
|
2024-11-21 11:18 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|