|
279991
|
- |
|
mailpoet
|
mailpoet_newsletters
|
Unspecified vulnerability in the MailPoet Newsletters (wysija-newsletters) plugin before 2.6.8 for WordPress has unspecified impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2014-4726
|
2024-11-21 11:10 |
2014-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279992
|
- |
|
mailpoet
|
mailpoet_newsletters
|
The MailPoet Newsletters (wysija-newsletters) plugin before 2.6.7 for WordPress allows remote attackers to bypass authentication and execute arbitrary PHP code by uploading a crafted theme using wp-a…
|
CWE-287
Improper Authentication
|
CVE-2014-4725
|
2024-11-21 11:10 |
2014-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279993
|
- |
|
gurock
|
testrail
|
Cross-site scripting (XSS) vulnerability in Gurock TestRail before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Created By field in a project activity.
|
CWE-79
Cross-site Scripting
|
CVE-2014-4857
|
2024-11-21 11:10 |
2014-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279994
|
- |
|
ibm
|
sametime
|
Cross-site scripting (XSS) vulnerability in the Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2014-4748
|
2024-11-21 11:10 |
2014-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279995
|
- |
|
ibm
|
sametime
|
The Classic Meeting Server in IBM Sametime 8.x through 8.5.2.1 allows physically proximate attackers to discover a meeting password hash by leveraging access to an unattended workstation to read HTML…
|
CWE-200
Information Exposure
|
CVE-2014-4747
|
2024-11-21 11:10 |
2014-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279996
|
- |
|
blogengine
|
e2
|
SQL injection vulnerability in E2 before 2.4 (2845) allows remote attackers to execute arbitrary SQL commands via the note-id parameter to @actions/comment-process.
|
CWE-89
SQL Injection
|
CVE-2014-4736
|
2024-11-21 11:10 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279997
|
- |
|
siemens
|
wincc simatic_pcs7
|
The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive infor…
|
NVD-CWE-Other
|
CVE-2014-4686
|
2024-11-21 11:10 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279998
|
- |
|
siemens
|
wincc simatic_pcs7
|
Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4685
|
2024-11-21 11:10 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279999
|
- |
|
siemens
|
wincc simatic_pcs7
|
The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a request to TCP port 1433.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4684
|
2024-11-21 11:10 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280000
|
- |
|
siemens
|
wincc simatic_pcs7
|
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a (1) HTTP or (2) HTTPS request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4683
|
2024-11-21 11:10 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|