|
277121
|
5.4 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbitrary web script or HTML via the "edit HTML source" option.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8707
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277122
|
5.3 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to …
|
CWE-200
Information Exposure
|
CVE-2014-8706
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277123
|
9.8 |
CRITICAL
Network
|
wondercms
|
wondercms
|
PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the hook parameter.
|
CWE-20
Improper Input Validation
|
CVE-2014-8705
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277124
|
9.8 |
CRITICAL
Network
|
wondercms
|
wondercms
|
Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted theme.
|
CWE-22
Path Traversal
|
CVE-2014-8704
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277125
|
6.1 |
MEDIUM
Network
|
wondercms
|
wondercms
|
Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8703
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277126
|
5.3 |
MEDIUM
Network
|
wondercms
|
wondercms
|
Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, which reveals the installation path in an error message.
|
CWE-200
Information Exposure
|
CVE-2014-8702
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277127
|
7.5 |
HIGH
Network
|
wondercms
|
wondercms
|
Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed password.
|
CWE-200
Information Exposure
|
CVE-2014-8701
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277128
|
7.5 |
HIGH
Network
|
telegram
|
messenger
|
An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android. Secret chat messages are available in cleartext in process memory and a .db file.
|
CWE-200
Information Exposure
|
CVE-2014-8688
|
2024-11-21 11:19 |
2017-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277129
|
8.1 |
HIGH
Network
|
avm
|
fritz\!_os
|
AVM FRITZ!OS before 6.30 extracts the contents of firmware updates before verifying their cryptographic signature, which allows remote attackers to create symlinks or overwrite critical files, and co…
|
CWE-310
Cryptographic Issues
|
CVE-2014-8886
|
2024-11-21 11:19 |
2016-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277130
|
- |
|
oracle
|
openjdk
|
A .desktop file in the Debian openjdk-7 package 7u79-2.5.5-1~deb8u1 includes a MIME type registration that is added to /etc/mailcap by mime-support, which allows remote attackers to execute arbitrary…
|
CWE-20
Improper Input Validation
|
CVE-2014-8873
|
2024-11-21 11:19 |
2015-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|