|
276901
|
5.3 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to …
|
CWE-200
Information Exposure
|
CVE-2014-8706
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276902
|
9.8 |
CRITICAL
Network
|
wondercms
|
wondercms
|
PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the hook parameter.
|
CWE-20
Improper Input Validation
|
CVE-2014-8705
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276903
|
9.8 |
CRITICAL
Network
|
wondercms
|
wondercms
|
Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted theme.
|
CWE-22
Path Traversal
|
CVE-2014-8704
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276904
|
6.1 |
MEDIUM
Network
|
wondercms
|
wondercms
|
Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8703
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276905
|
5.3 |
MEDIUM
Network
|
wondercms
|
wondercms
|
Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2014-8702
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276906
|
7.5 |
HIGH
Network
|
wondercms
|
wondercms
|
Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed password.
|
CWE-200
Information Exposure
|
CVE-2014-8701
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276907
|
7.5 |
HIGH
Network
|
telegram
|
messenger
|
An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android. Secret chat messages are available in cleartext in process memory and a .db file.
|
CWE-200
Information Exposure
|
CVE-2014-8688
|
2024-11-21 11:19 |
2017-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276908
|
8.1 |
HIGH
Network
|
avm
|
fritz\!_os
|
AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote attackers to create symlinks or overwrite critical files, and co…
|
CWE-310
Cryptographic Issues
|
CVE-2014-8886
|
2024-11-21 11:19 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276909
|
- |
|
oracle
|
openjdk
|
A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary…
|
CWE-20
Improper Input Validation
|
CVE-2014-8873
|
2024-11-21 11:19 |
2015-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276910
|
- |
|
ibm
|
websphere_portal
|
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0.0 through 7.0.0.2 CF29, 8.0.0 through 8.0.0.1 CF18, and 8.5.0 before CF08 improperly restricts resource access, which …
|
CWE-284
Improper Access Control
|
CVE-2014-8912
|
2024-11-21 11:19 |
2015-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|