|
276971
|
- |
|
proticaret
|
proticaret
|
SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a tem:Code element in a SOAP request.
|
CWE-89
SQL Injection
|
CVE-2014-9237
|
2024-11-21 11:20 |
2014-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276972
|
- |
|
zoph
|
zoph
|
Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) photog…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9236
|
2024-11-21 11:20 |
2014-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276973
|
- |
|
zoph
|
zoph
|
Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.…
|
CWE-89
SQL Injection
|
CVE-2014-9235
|
2024-11-21 11:20 |
2014-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276974
|
- |
|
d-link
|
dcs-2103_hd_cube_network_camera_firmware
|
Directory traversal vulnerability in cgi-bin/sddownload.cgi in D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
|
CWE-22
Path Traversal
|
CVE-2014-9234
|
2024-11-21 11:20 |
2014-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276975
|
- |
|
debian graphviz
|
debian_linux graphviz
|
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not …
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2014-9157
|
2024-11-21 11:20 |
2014-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276976
|
- |
|
huawei
|
honor_cube_wireless_router_ws860s_firewall honor_cube_wireless_router_ws860s
|
Unrestricted file upload vulnerability in Huawei Honor Cube Wireless Router WS860s before V100R001C02B222 allows remote attackers to execute arbitrary code by uploading a file with an executable exte…
|
NVD-CWE-Other
|
CVE-2014-9134
|
2024-11-21 11:20 |
2014-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276977
|
- |
|
icecast
|
icecast
|
Icecast before 2.4.1 transmits the output of the on-connect script, which might allow remote attackers to obtain sensitive information, related to shared file descriptors.
|
CWE-200
Information Exposure
|
CVE-2014-9018
|
2024-11-21 11:20 |
2014-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276978
|
- |
|
fedoraproject openvas opensuse
|
fedora openvas_manager opensuse
|
SQL injection vulnerability in OpenVAS Manager before 4.0.6 and 5.x before 5.0.7 allows remote attackers to execute arbitrary SQL commands via the timezone parameter in a modify_schedule OMP command.
|
CWE-89
SQL Injection
|
CVE-2014-9220
|
2024-11-21 11:20 |
2014-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276979
|
- |
|
thomsonreuters
|
fixed_assets_cs
|
The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9141
|
2024-11-21 11:20 |
2014-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276980
|
- |
|
zte
|
zxdsl
|
ZTE ZXDSL 831CII allows remote attackers to bypass authentication via a direct request to (1) main.cgi, (2) adminpasswd.cgi, (3) userpasswd.cgi, (4) upload.cgi, (5) conprocess.cgi, or (6) connect.cgi.
|
CWE-287
Improper Authentication
|
CVE-2014-9184
|
2024-11-21 11:20 |
2014-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|