|
280421
|
- |
|
kryo
|
iodine
|
(1) iodined.c and (2) user.c in iodine before 0.7.0 allows remote attackers to bypass authentication by continuing execution after an error has been triggering.
|
CWE-287
Improper Authentication
|
CVE-2014-4168
|
2024-11-21 11:09 |
2014-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280422
|
- |
|
aas9
|
zerocms
|
Cross-site scripting (XSS) vulnerability in zero_view_article.php in ZeroCMS 1.0 allows remote attackers to inject arbitrary web script or HTML via the article_id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2014-4195
|
2024-11-21 11:09 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280423
|
- |
|
opensuse cacti
|
opensuse cacti
|
Multiple cross-site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the (1) drp_action parameter to cdef.php, (2) data_input.php, (3)…
|
CWE-79
Cross-site Scripting
|
CVE-2014-4002
|
2024-11-21 11:09 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280424
|
- |
|
kanboard
|
kanboard
|
Cross-site request forgery (CSRF) vulnerability in Kanboard before 1.0.6 allows remote attackers to hijack the authentication of administrators for requests that add an administrative user via a save…
|
CWE-352
Origin Validation Error
|
CVE-2014-3920
|
2024-11-21 11:09 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280425
|
- |
|
kerio
|
control
|
Multiple SQL injection vulnerabilities in Kerio Control Statistics in Kerio Control (formerly WinRoute Firewall) before 8.3.2 allow remote authenticated users to execute arbitrary SQL commands via th…
|
CWE-89
SQL Injection
|
CVE-2014-3857
|
2024-11-21 11:09 |
2014-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280426
|
- |
|
silex
|
sx-2000wg_firmware
|
silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via a crafted IP packet, a different vulnerability than CVE-2014-3889.
|
CWE-20
Improper Input Validation
|
CVE-2014-3890
|
2024-11-21 11:09 |
2014-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280427
|
- |
|
silex
|
sx-2000wg_firmware
|
silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via crafted data in the Options field of a TCP header, a different vulnera…
|
CWE-20
Improper Input Validation
|
CVE-2014-3889
|
2024-11-21 11:09 |
2014-07-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280428
|
- |
|
intercom
|
web_kyukincho
|
Cross-site request forgery (CSRF) vulnerability in Intercom Web Kyukincho 3.x before 3.0.030 allows remote attackers to hijack the authentication of arbitrary users.
|
CWE-352
Origin Validation Error
|
CVE-2014-3881
|
2024-11-21 11:09 |
2014-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280429
|
- |
|
longtailvideo
|
jw_player_for_flash_\&_html5_video_plugin
|
Cross-site request forgery (CSRF) vulnerability in the JW Player plugin before 2.1.4 for WordPress allows remote attackers to hijack the authentication of administrators for requests that remove play…
|
CWE-352
Origin Validation Error
|
CVE-2014-4030
|
2024-11-21 11:09 |
2014-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280430
|
- |
|
12net
|
login_rebuilder
|
Cross-site request forgery (CSRF) vulnerability in the Login rebuilder plugin before 1.2.0 for WordPress allows remote attackers to hijack the authentication of arbitrary users.
|
CWE-352
Origin Validation Error
|
CVE-2014-3882
|
2024-11-21 11:09 |
2014-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|