|
278261
|
8.8 |
HIGH
Network
|
phpmyfaq
|
phpmyfaq
|
Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication of unspecified users for requests that (1) delete active users…
|
CWE-352
Origin Validation Error
|
CVE-2014-6046
|
2024-11-21 11:13 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278262
|
7.2 |
HIGH
Network
|
phpmyfaq
|
phpmyfaq
|
SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via vectors involving the restore function.
|
CWE-89
SQL Injection
|
CVE-2014-6045
|
2024-11-21 11:13 |
2018-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278263
|
5.9 |
MEDIUM
Network
|
ibm
|
security_identity_manager tivoli_identity_manager
|
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 make it easier for remote at…
|
CWE-200
Information Exposure
|
CVE-2014-6112
|
2024-11-21 11:13 |
2018-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278264
|
7.8 |
HIGH
Local
|
ibm
|
security_identity_manager tivoli_identity_manager
|
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 store encrypted user credent…
|
CWE-255
Credentials Management
|
CVE-2014-6111
|
2024-11-21 11:13 |
2018-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278265
|
5.3 |
MEDIUM
Network
|
ibm
|
security_identity_manager tivoli_identity_manager
|
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 allow remote authenticated u…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2014-6109
|
2024-11-21 11:13 |
2018-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278266
|
5.9 |
MEDIUM
Network
|
ibm
|
security_identity_manager tivoli_identity_manager
|
IBM Tivoli Identity Manager 5.1.x before 5.1.0.15-ISS-TIM-IF0057 and Security Identity Manager 6.0.x before 6.0.0.4-ISS-SIM-IF0001 and 7.0.x before 7.0.0.0-ISS-SIM-IF0003 might allow man-in-the-middl…
|
CWE-200
Information Exposure
|
CVE-2014-6108
|
2024-11-21 11:13 |
2018-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278267
|
5.4 |
MEDIUM
Network
|
ibm
|
forms_experience_builder
|
Cross-site scripting (XSS) vulnerability in IBM Forms Experience Builder 8.5.0 and 8.5.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 97777.
|
CWE-79
Cross-site Scripting
|
CVE-2014-6169
|
2024-11-21 11:13 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278268
|
9.8 |
CRITICAL
Network
|
ibm
|
rational_appscan_source security_appscan_source
|
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow remote attacker…
|
CWE-77
Command Injection
|
CVE-2014-6120
|
2024-11-21 11:13 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278269
|
6.1 |
MEDIUM
Network
|
jquery
|
jquery
|
jQuery 1.4.2 allows remote attackers to conduct cross-site scripting (XSS) attacks via vectors related to use of the text method inside after.
|
CWE-79
Cross-site Scripting
|
CVE-2014-6071
|
2024-11-21 11:13 |
2018-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278270
|
6.1 |
MEDIUM
Network
|
torrentflux_project
|
torrentflux
|
Multiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.4 allow (1) remote attackers to inject arbitrary web script or HTML by leveraging failure to encode file contents when downloading…
|
CWE-79
Cross-site Scripting
|
CVE-2014-6027
|
2024-11-21 11:13 |
2018-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|