|
277881
|
9.8 |
CRITICAL
Network
|
phpmemcachedadmin_project
|
phpmemcachedadmin
|
PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2014-8731
|
2024-11-21 11:19 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277882
|
5.3 |
MEDIUM
Network
|
get-simple
|
getsimple_cms
|
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation …
|
CWE-200
Information Exposure
|
CVE-2014-8723
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277883
|
7.5 |
HIGH
Network
|
get-simple
|
getsimple_cms
|
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<username>.xml.bak, (3) data/other/authorization.x…
|
CWE-200
Information Exposure
|
CVE-2014-8722
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277884
|
9.8 |
CRITICAL
Network
|
pluck-cms
|
pluck
|
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8708
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277885
|
5.4 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbitrary web script or HTML via the "edit HTML source" option.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8707
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277886
|
5.3 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to …
|
CWE-200
Information Exposure
|
CVE-2014-8706
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277887
|
9.8 |
CRITICAL
Network
|
wondercms
|
wondercms
|
PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the hook parameter.
|
CWE-20
Improper Input Validation
|
CVE-2014-8705
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277888
|
9.8 |
CRITICAL
Network
|
wondercms
|
wondercms
|
Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted theme.
|
CWE-22
Path Traversal
|
CVE-2014-8704
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277889
|
6.1 |
MEDIUM
Network
|
wondercms
|
wondercms
|
Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8703
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277890
|
5.3 |
MEDIUM
Network
|
wondercms
|
wondercms
|
Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2014-8702
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|