|
277211
|
- |
|
c97
|
cart_engine
|
SQL injection vulnerability in the sql_query function in cart.php in C97net Cart Engine before 4.0 allows remote attackers to execute arbitrary SQL commands via the item_id variable, as demonstrated …
|
CWE-89
SQL Injection
|
CVE-2014-8306
|
2024-11-21 11:18 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277212
|
- |
|
c97
|
cart_engine
|
Open redirect vulnerability in the redir function in includes/function.php in C97net Cart Engine before 4.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attac…
|
NVD-CWE-Other
|
CVE-2014-8305
|
2024-11-21 11:18 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277213
|
- |
|
in-portal
|
in-portal
|
Cross-site scripting (XSS) vulnerability in In-Portal CMS 5.2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the next_template parameter to admin/index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8304
|
2024-11-21 11:18 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277214
|
- |
|
splunk
|
splunk
|
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4 and 6.0.x before 6.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors relate…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8303
|
2024-11-21 11:18 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277215
|
- |
|
splunk
|
splunk
|
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4, 6.0.x before 6.0.6, and 5.0.x before 5.0.10 allows remote attackers to inject arbitrary web script or H…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8302
|
2024-11-21 11:18 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277216
|
- |
|
splunk
|
splunk
|
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 5.0.x before 5.0.10 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8301
|
2024-11-21 11:18 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277217
|
- |
|
tigervnc
|
tigervnc
|
Integer overflow in TigerVNC allows remote VNC servers to cause a denial of service (crash) and possibly execute arbitrary code via vectors related to screen size handling, which triggers a heap-base…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-8240
|
2024-11-21 11:18 |
2014-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277218
|
- |
|
drupal
|
modal_frame
|
Cross-site scripting (XSS) vulnerability in the Modal Frame API module 6.x-1.x before 6.x-1.9 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8296
|
2024-11-21 11:18 |
2014-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277219
|
- |
|
bacula
|
bacula-web
|
SQL injection vulnerability in joblogs.php in Bacula-Web 5.2.10 allows remote attackers to execute arbitrary SQL commands via the jobid parameter.
|
CWE-89
SQL Injection
|
CVE-2014-8295
|
2024-11-21 11:18 |
2014-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277220
|
- |
|
php_resource
|
voice_of_web_allmyguests
|
Multiple SQL injection vulnerabilities in Voice Of Web AllMyGuests 0.4.1 allow remote attackers to execute arbitrary SQL commands via the (1) allmyphp_cookie cookie to admin.php or the (2) Username o…
|
CWE-89
SQL Injection
|
CVE-2014-8294
|
2024-11-21 11:18 |
2014-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|