|
279651
|
- |
|
netfortris
|
trixbox
|
maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter.
|
CWE-94
Code Injection
|
CVE-2014-5112
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279652
|
- |
|
netfortris
|
trixbox
|
Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to (1) home/index.php, (2) asterisk_info/aster…
|
CWE-22
Path Traversal
|
CVE-2014-5111
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279653
|
- |
|
netfortris
|
trixbox
|
Cross-site scripting (XSS) vulnerability in user/help/html/index.php in Fonality trixbox allows remote attackers to inject arbitrary web script or HTML via the id_nodo parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2014-5110
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279654
|
- |
|
netfortris
|
trixbox
|
SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL commands via the mac parameter in a Submit action.
|
CWE-89
SQL Injection
|
CVE-2014-5109
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279655
|
- |
|
concrete5 concretecms
|
concrete5 concrete_cms
|
Cross-site scripting (XSS) vulnerability in single_pages\download_file.php in concrete5 before 5.6.3 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header to inde…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5108
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279656
|
- |
|
concrete5 concretecms
|
concrete5 concrete_cms
|
concrete5 before 5.6.3 allows remote attackers to obtain the installation path via a direct request to (1) system/basics/editor.php, (2) system/view.php, (3) system/environment/file_storage_locations…
|
CWE-200
Information Exposure
|
CVE-2014-5107
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279657
|
- |
|
invisioncommunity
|
invision_power_board
|
Cross-site scripting (XSS) vulnerability in Invision Power IP.Board (aka IPB or Power Board) 3.4.x through 3.4.6 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer he…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5106
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279658
|
- |
|
ol-commerce_project
|
ol-commerce
|
Multiple cross-site scripting (XSS) vulnerabilities in ol-commerce 2.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) a_country parameter in a process action to affiliate…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5105
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279659
|
- |
|
ol-commerce_project
|
ol-commerce
|
Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) a_country parameter in a process action to affiliate_signup.php, (2) a…
|
CWE-89
SQL Injection
|
CVE-2014-5104
|
2024-11-21 11:11 |
2014-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279660
|
- |
|
microsoft
|
windows_xp
|
Microsoft Windows XP SP3 does not validate addresses in certain IRP handler routines, which allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a cra…
|
CWE-20
Improper Input Validation
|
CVE-2014-4971
|
2024-11-21 11:11 |
2014-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|