|
276431
|
- |
|
infinitewp
|
infinitewp
|
Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is set, allows remote attackers to execute arbitrary code by upl…
|
CWE-94
Code Injection
|
CVE-2014-9521
|
2024-11-21 11:21 |
2015-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276432
|
- |
|
infinitewp
|
infinitewp
|
SQL injection vulnerability in execute.php in InfiniteWP Admin Panel before 2.4.4 allows remote attackers to execute arbitrary SQL commands via the historyID parameter.
|
CWE-89
SQL Injection
|
CVE-2014-9520
|
2024-11-21 11:21 |
2015-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276433
|
- |
|
infinitewp
|
infinitewp
|
SQL injection vulnerability in login.php in InfiniteWP Admin Panel before 2.4.3 allows remote attackers to execute arbitrary SQL commands via the email parameter.
|
CWE-89
SQL Injection
|
CVE-2014-9519
|
2024-11-21 11:21 |
2015-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276434
|
- |
|
d-link
|
dir-655_firmware dir-655
|
Cross-site scripting (XSS) vulnerability in login.cgi in D-Link router DIR-655 (rev Bx) with firmware before 2.12b01 allows remote attackers to inject arbitrary web script or HTML via the html_respon…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9518
|
2024-11-21 11:21 |
2015-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276435
|
- |
|
dlink
|
dcs-2103_firmware
|
Cross-site scripting (XSS) vulnerability in D-link IP camera DCS-2103 with firmware before 1.20 allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING to vb.htm.
|
CWE-79
Cross-site Scripting
|
CVE-2014-9517
|
2024-11-21 11:21 |
2015-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276436
|
- |
|
social_microblogging_pro_project
|
social_microblogging_pro
|
Cross-site scripting (XSS) vulnerability in Social Microblogging PRO 1.5 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to the default URI, related to the "Web Site"…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9516
|
2024-11-21 11:21 |
2015-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276437
|
- |
|
typo3
|
typo3
|
The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set to all or cached, allows remote attackers …
|
CWE-20
Improper Input Validation
|
CVE-2014-9509
|
2024-11-21 11:21 |
2015-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276438
|
- |
|
typo3
|
typo3
|
The frontend rendering component in TYPO3 4.5.x before 4.5.39, 4.6.x through 6.2.x before 6.2.9, and 7.x before 7.0.2, when config.prefixLocalAnchors is set and using a homepage with links that only …
|
CWE-59
Link Following
|
CVE-2014-9508
|
2024-11-21 11:21 |
2015-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276439
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki 1.21.x, 1.22.x before 1.22.14, and 1.23.x before 1.23.7, when $wgContentHandlerUseDB is enabled, allows remote attackers to conduct cross-site scripting (XSS) attacks by setting the content…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9507
|
2024-11-21 11:21 |
2015-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276440
|
- |
|
mantisbt
|
mantisbt
|
MantisBT before 1.2.18 does not properly check permissions when sending an email that indicates when a monitored issue is related to another issue, which allows remote authenticated users to obtain s…
|
CWE-200
Information Exposure
|
CVE-2014-9506
|
2024-11-21 11:21 |
2015-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|