|
282811
|
6.1 |
MEDIUM
Local
|
perl
|
dbi
|
An issue was discovered in the DBI module before 1.632 for Perl. DBD::File drivers can open files from folders other than those specifically passed via the f_dir attribute.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2014-10401
|
2024-11-21 11:03 |
2020-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282812
|
6.1 |
MEDIUM
Network
|
keplerproject
|
cgilua
|
The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this vulnerability was S…
|
CWE-384
Session Fixation
|
CVE-2014-10400
|
2024-11-21 11:03 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282813
|
6.1 |
MEDIUM
Network
|
keplerproject
|
cgilua
|
The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-2014-2875.
|
CWE-384
Session Fixation
|
CVE-2014-10399
|
2024-11-21 11:03 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282814
|
6.1 |
MEDIUM
Network
|
bssys
|
rbs_bs-client._retail_client
|
Multiple cross-site scripting (XSS) vulnerabilities in bsi.dll in Bank Soft Systems (BSS) RBS BS-Client. Private Client (aka RBS BS-Client. Retail Client) 2.5, 2.4, and earlier allow remote attackers…
|
CWE-79
Cross-site Scripting
|
CVE-2014-10398
|
2024-11-21 11:03 |
2020-01-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282815
|
6.1 |
MEDIUM
Network
|
ideagen
|
q-pulse
|
Cross-site scripting (XSS) vulnerability in ui/common/managedlistdialog.aspx in Gael Q-Pulse 0.6 and earlier.
|
CWE-79
Cross-site Scripting
|
CVE-2014-1238
|
2024-11-21 11:03 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282816
|
8.8 |
HIGH
Network
|
projoom
|
smart_flash_header
|
views/upload.php in the ProJoom Smart Flash Header (NovaSFH) component 3.0.2 and earlier for Joomla! allows remote attackers to upload and execute arbitrary files via a crafted (1) dest parameter and…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2014-1214
|
2024-11-21 11:03 |
2019-11-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282817
|
7.5 |
HIGH
Network
|
para
|
antioch
|
The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts/download.php.
|
CWE-22
Path Traversal
|
CVE-2014-10397
|
2024-11-21 11:03 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282818
|
7.5 |
HIGH
Network
|
organizedthemes
|
epic
|
The epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.
|
CWE-22
Path Traversal
|
CVE-2014-10396
|
2024-11-21 11:03 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282819
|
6.1 |
MEDIUM
Network
|
codepeople
|
polls_cp
|
The cp-polls plugin before 1.0.1 for WordPress has XSS in the votes list.
|
CWE-79
Cross-site Scripting
|
CVE-2014-10395
|
2024-11-21 11:03 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282820
|
6.1 |
MEDIUM
Network
|
cformsii_project
|
cformsii
|
The cforms2 plugin before 10.5 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2014-10393
|
2024-11-21 11:03 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|