|
279821
|
- |
|
wordfence_security_project
|
wordfence_security
|
Cross-site scripting (XSS) vulnerability in the Wordfence Security plugin before 5.1.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via the whoisval parameter on the W…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4664
|
2024-11-21 11:10 |
2014-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279822
|
- |
|
ibm
|
websphere_commerce
|
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 does not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (memory and …
|
NVD-CWE-Other
|
CVE-2014-4834
|
2024-11-21 11:10 |
2014-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279823
|
- |
|
ibm
|
cognos_mobile
|
IBM Cognos Mobile 10.1.1 before FP3 IF1, 10.2.0 before FP2 IF1, and 10.2.1 before FP4 IF1 preserves a session between the Cognos Mobile server and the Cognos Business Intelligence server after a logo…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4810
|
2024-11-21 11:10 |
2014-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279824
|
- |
|
ibm
|
websphere_commerce
|
IBM WebSphere Commerce 6.x through 6.0.0.11 and 7.x through 7.0.0.8 allows remote authenticated users to read arbitrary files or send TCP requests to intranet servers via XML data containing an exter…
|
NVD-CWE-Other
|
CVE-2014-4769
|
2024-11-21 11:10 |
2014-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279825
|
- |
|
ibm
|
tririga_application_platform
|
Cross-site request forgery (CSRF) vulnerability in birtviewer.query in IBM TRIRIGA Application Platform 3.2 and 3.3 before 3.3.0.2, 3.3.1 before 3.3.1.3, 3.3.2 before 3.3.2.2, and 3.4 before 3.4.0.1 …
|
CWE-352
Origin Validation Error
|
CVE-2014-4839
|
2024-11-21 11:10 |
2014-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279826
|
- |
|
ibm
|
websphere_portal
|
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 provides different web-server error codes depend…
|
CWE-200
Information Exposure
|
CVE-2014-4821
|
2024-11-21 11:10 |
2014-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279827
|
- |
|
ibm
|
websphere_portal
|
IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 does not properly detect recursion during entity…
|
CWE-399
Resource Management Errors
|
CVE-2014-4814
|
2024-11-21 11:10 |
2014-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279828
|
- |
|
ibm
|
websphere_portal
|
Unspecified vulnerability in IBM WebSphere Portal 6.1.0 through 6.1.0.6 CF27, 6.1.5 through 6.1.5.3 CF27, 7.0 through 7.0.0.2 CF28, 8.0 through 8.0.0.1 CF14, and 8.5.0 before CF03 allows remote authe…
|
NVD-CWE-noinfo
|
CVE-2014-4808
|
2024-11-21 11:10 |
2014-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279829
|
- |
|
wp-football_project
|
wp-football
|
Multiple cross-site scripting (XSS) vulnerabilities in the wp-football plugin 1.1 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the league parameter to (…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4586
|
2024-11-21 11:10 |
2014-10-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279830
|
- |
|
ibm
|
security_appscan_source
|
The installer in IBM Security AppScan Source 8.x and 9.x through 9.0.1 has an open network port for a debug service, which allows remote attackers to obtain sensitive information by connecting to thi…
|
CWE-200
Information Exposure
|
CVE-2014-4812
|
2024-11-21 11:10 |
2014-10-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|