|
279371
|
9.8 |
CRITICAL
Network
|
zend debian
|
zend_framework debian_linux
|
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2014-4914
|
2024-11-21 11:11 |
2017-12-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279372
|
7.2 |
HIGH
Network
|
landesk
|
landesk_management_suite
|
The admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving ASPX pages from third-party sites via the d parameter to (1)…
|
CWE-20
Improper Input Validation
|
CVE-2014-5362
|
2024-11-21 11:11 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279373
|
8.8 |
HIGH
Network
|
manageengine
|
servicedesk_plus assetexplorer supportcenter it360
|
Directory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4 allows remote authenticated users to ex…
|
CWE-22
Path Traversal
|
CVE-2014-5302
|
2024-11-21 11:11 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279374
|
8.8 |
HIGH
Network
|
manageengine
|
servicedesk_plus assetexplorer supportcenter it360
|
Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.
|
CWE-22
Path Traversal
|
CVE-2014-5301
|
2024-11-21 11:11 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279375
|
6.1 |
MEDIUM
Network
|
good
|
good_for_enterprise
|
Cross-site scripting (XSS) vulnerability in Good for Enterprise for Android 2.8.0.398 and 1.9.0.40.
|
CWE-79
Cross-site Scripting
|
CVE-2014-4925
|
2024-11-21 11:11 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279376
|
5.4 |
MEDIUM
Network
|
telescopeapp
|
telescope
|
Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted markdown.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5144
|
2024-11-21 11:11 |
2017-08-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279377
|
9.8 |
CRITICAL
Network
|
snoopy redhat nagios
|
snoopy openstack nagios
|
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.
|
CWE-77
Command Injection
|
CVE-2014-5009
|
2024-11-21 11:11 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279378
|
9.8 |
CRITICAL
Network
|
snoopy redhat debian
|
snoopy openstack debian_linux
|
Snoopy allows remote attackers to execute arbitrary commands.
|
CWE-77
Command Injection
|
CVE-2014-5008
|
2024-11-21 11:11 |
2017-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279379
|
6.8 |
MEDIUM
Network
|
eucalyptus
|
eucalyptus
|
HP Helion Eucalyptus 4.1.x before 4.1.2 and HPE Helion Eucalyptus 4.2.x before 4.2.1 allow remote authenticated users to bypass intended access restrictions and modify arbitrary (1) access key creden…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-5040
|
2024-11-21 11:11 |
2016-01-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279380
|
3.7 |
LOW
Network
|
toshiba
|
4690_operating_system
|
Toshiba 4690 Operating System 6 Release 3, when the ADXSITCF logical name is not properly restricted, allows remote attackers to read potentially sensitive system environment variables via a crafted …
|
CWE-200
Information Exposure
|
CVE-2014-4876
|
2024-11-21 11:11 |
2015-12-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|