|
277831
|
5.4 |
MEDIUM
Network
|
piwigo
|
lexiglot
|
Lexiglot through 2014-11-20 allows XSS (Reflected) via the username, or XSS (Stored) via the admin.php?page=config install_name, intro_message, or new_file_content parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8944
|
2024-11-21 11:19 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277832
|
8.8 |
HIGH
Network
|
piwigo
|
lexiglot
|
Lexiglot through 2014-11-20 allows SSRF via the admin.php?page=projects svn_url parameter.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2014-8943
|
2024-11-21 11:19 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277833
|
8.8 |
HIGH
Network
|
piwigo
|
lexiglot
|
Lexiglot through 2014-11-20 allows CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2014-8942
|
2024-11-21 11:19 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277834
|
9.8 |
CRITICAL
Network
|
piwigo
|
lexiglot
|
Lexiglot through 2014-11-20 allows SQL injection via an admin.php?page=users&from_id= or admin.php?page=history&limit= URI.
|
CWE-89
SQL Injection
|
CVE-2014-8941
|
2024-11-21 11:19 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277835
|
5.3 |
MEDIUM
Network
|
piwigo
|
lexiglot
|
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (names and details of projects) by visiting the /update.log URI.
|
CWE-200
Information Exposure
|
CVE-2014-8940
|
2024-11-21 11:19 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277836
|
5.3 |
MEDIUM
Network
|
piwigo
|
lexiglot
|
Lexiglot through 2014-11-20 allows remote attackers to obtain sensitive information (full path) via an include/smarty/plugins/modifier.date_format.php request if PHP has a non-recommended configurati…
|
CWE-22
Path Traversal
|
CVE-2014-8939
|
2024-11-21 11:19 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277837
|
7.8 |
HIGH
Local
|
piwigo
|
lexiglot
|
Lexiglot through 2014-11-20 allows local users to obtain sensitive information by listing a process because the username and password are on the command line.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2014-8938
|
2024-11-21 11:19 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277838
|
7.5 |
HIGH
Network
|
piwigo
|
lexiglot
|
Lexiglot through 2014-11-20 allows denial of service because api/update.php launches svn update operations that use a great deal of resources.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2014-8937
|
2024-11-21 11:19 |
2020-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277839
|
9.8 |
CRITICAL
Network
|
jquery_file_upload_project creative-solutions
|
jquery_file_upload creative_contact_form
|
Unrestricted file upload vulnerability in server/php/UploadHandler.php in the jQuery File Upload Plugin 6.4.4 for jQuery, as used in the Creative Solutions Creative Contact Form (formerly Sexy Contac…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2014-8739
|
2024-11-21 11:19 |
2020-02-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277840
|
6.1 |
MEDIUM
Network
|
tennisconnect
|
components
|
Cross-site scripting (XSS) vulnerability in TennisConnect COMPONENTS 9.927 allows remote attackers to inject arbitrary web script or HTML via the pid parameter to index.cfm.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8490
|
2024-11-21 11:19 |
2020-01-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|