|
277611
|
- |
|
ipa
|
ilogscanner
|
Cross-site scripting (XSS) vulnerability in IPA iLogScanner 4.0 allows remote attackers to inject arbitrary web script or HTML by triggering a crafted entry in a log file.
|
CWE-79
Cross-site Scripting
|
CVE-2014-7248
|
2024-11-21 11:16 |
2014-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277612
|
- |
|
forgerock
|
openam
|
The Core Server in OpenAM 9.5.3 through 9.5.5, 10.0.0 through 10.0.2, 10.1.0-Xpress, and 11.0.0 through 11.0.2, when deployed on a multi-server network, allows remote authenticated users to cause a d…
|
CWE-20
Improper Input Validation
|
CVE-2014-7246
|
2024-11-21 11:16 |
2014-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277613
|
- |
|
linux
|
linux_kernel
|
A certain Debian patch to the IPv6 implementation in the Linux kernel 3.2.x through 3.2.63 does not properly validate arguments in ipv6_select_ident function calls, which allows local users to cause …
|
NVD-CWE-Other
|
CVE-2014-7207
|
2024-11-21 11:16 |
2014-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277614
|
- |
|
enalean
|
tuleap
|
SQL injection vulnerability in Enalean Tuleap before 7.5.99.4 allows remote authenticated users to execute arbitrary SQL commands via the lobal_txt parameter to plugins/docman.
|
CWE-89
SQL Injection
|
CVE-2014-7176
|
2024-11-21 11:16 |
2014-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277615
|
- |
|
joomla
|
joomla\!
|
Akeeba Restore (restore.php), as used in Joomla! 2.5.4 through 2.5.25, 3.x through 3.2.5, and 3.3.0 through 3.3.4; Akeeba Backup for Joomla! Professional 3.0.0 through 4.0.2; Backup Professional for …
|
CWE-310
Cryptographic Issues
|
CVE-2014-7228
|
2024-11-21 11:16 |
2014-11-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277616
|
- |
|
enalean
|
tuleap
|
XML External Entity vulnerability in Enalean Tuleap 7.2 and earlier allows remote authenticated users to read arbitrary files via a crafted xml document in a create action to plugins/tracker/.
|
NVD-CWE-Other
|
CVE-2014-7177
|
2024-11-21 11:16 |
2014-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277617
|
- |
|
electric_cloud
|
electriccommander
|
Electric Cloud ElectricCommander before 4.2.6 and 5.x before 5.0.3 uses world-writable permissions for (1) eccert.pl and (2) ecconfigure.pl, which allows local users to execute arbitrary Perl code by…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-7180
|
2024-11-21 11:16 |
2014-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277618
|
- |
|
centrify
|
directcontrol centrify_suite
|
adsetgroups in Centrify Server Suite 2008 through 2014.1 and Centrify DirectControl 3.x through 4.2.0 on Linux and UNIX allows local users to read arbitrary files with root privileges by leveraging i…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-7298
|
2024-11-21 11:16 |
2014-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277619
|
- |
|
newtelligence
|
dasblog
|
Open redirect vulnerability in the Click-Through feature in Newtelligence dasBlog 2.1 (2.1.8102.813), 2.2 (2.2.8279.16125), and 2.3 (2.3.9074.18820) allows remote attackers to redirect users to arbit…
|
NVD-CWE-Other
|
CVE-2014-7292
|
2024-11-21 11:16 |
2014-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277620
|
- |
|
tenda
|
a32_firmware a32
|
Cross-site request forgery (CSRF) vulnerability in Shenzhen Tenda Technology Tenda A32 Router with firmware 5.07.53_CN allows remote attackers to hijack the authentication of administrators for reque…
|
CWE-352
Origin Validation Error
|
CVE-2014-7281
|
2024-11-21 11:16 |
2014-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|