|
276311
|
6.1 |
MEDIUM
Network
|
flowpaper
|
flexpaper
|
Cross-site scripting (XSS) vulnerability in FlexPaperViewer.swf in Flexpaper before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the Swfile parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2014-9677
|
2024-11-21 11:21 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276312
|
8.8 |
HIGH
Network
|
gollum_project
|
gollum gollum-lib grit_adapter
|
The gollum-grit_adapter Ruby gem dependency in gollum before 3.1.1 and the gollum-lib gem dependency in gollum-lib before 4.0.1 when the string "master" is in any of the wiki documents, allows remote…
|
CWE-284
Improper Access Control
|
CVE-2014-9489
|
2024-11-21 11:21 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276313
|
9.8 |
CRITICAL
Network
|
mediawiki
|
mediawiki
|
The getid3 library in MediaWiki before 1.24.1, 1.23.8, 1.22.15 and 1.19.23 allows remote attackers to read arbitrary files, cause a denial of service, or possibly have other impact via an XML Externa…
|
CWE-611
XXE
|
CVE-2014-9487
|
2024-11-21 11:21 |
2017-10-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276314
|
5.9 |
MEDIUM
Network
|
mapsplugin
|
googlemaps
|
The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_goog…
|
CWE-399
Resource Management Errors
|
CVE-2014-9686
|
2024-11-21 11:21 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276315
|
6.1 |
MEDIUM
Network
|
magento
|
magento
|
Cross-site scripting (XSS) vulnerability in Magento E-Commerce Platform 1.9.0.1.
|
CWE-79
Cross-site Scripting
|
CVE-2014-9758
|
2024-11-21 11:21 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276316
|
7.2 |
HIGH
Network
|
netsweeper
|
netsweeper
|
Unrestricted file upload vulnerability in webadmin/ajaxfilemanager/ajaxfilemanager.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote authenticated users with a…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2014-9619
|
2024-11-21 11:21 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276317
|
9.8 |
CRITICAL
Network
|
netsweeper
|
netsweeper
|
The Client Filter Admin portal in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and subsequently create arbitrary profiles via …
|
CWE-287
Improper Authentication
|
CVE-2014-9618
|
2024-11-21 11:21 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276318
|
7.5 |
HIGH
Network
|
netsweeper
|
netsweeper
|
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to obtain sensitive information by making a request that redirects to the deny page.
|
CWE-200
Information Exposure
|
CVE-2014-9616
|
2024-11-21 11:21 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276319
|
9.8 |
CRITICAL
Network
|
netsweeper
|
netsweeper
|
Netsweeper before 4.0.5 allows remote attackers to bypass authentication and create arbitrary accounts and policies via a request to webadmin/nslam/index.php.
|
CWE-287
Improper Authentication
|
CVE-2014-9611
|
2024-11-21 11:21 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276320
|
5.3 |
MEDIUM
Network
|
netsweeper
|
netsweeper
|
Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to bypass authentication and remove IP addresses from the quarantine via the ip parameter to webadmin/user…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9610
|
2024-11-21 11:21 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|