|
277811
|
- |
|
twilio_project
|
twilio
|
The Twilio module 7.x-1.x before 7.x-1.9 for Drupal does not properly restrict access to the Twilio administration pages, which allows remote authenticated users to read and modify authentication tok…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9023
|
2024-11-21 11:20 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277812
|
- |
|
web_component_roles_project
|
web_component_roles
|
The Webform Component Roles module 6.x-1.x before 6.x-1.8 and 7.x-1.x before 7.x-1.8 for Drupal allows remote attackers to bypass the "disabled" restriction and modify read-only components via a craf…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9022
|
2024-11-21 11:20 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277813
|
- |
|
zteusa
|
zxdsl_831
|
Multiple cross-site scripting (XSS) vulnerabilities in ZTE ZXDSL 831 allow remote attackers to inject arbitrary web script or HTML via the (1) tr69cAcsURL, (2) tr69cAcsUser, (3) tr69cAcsPwd, (4) tr69…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9021
|
2024-11-21 11:20 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277814
|
- |
|
zte
|
zxdsl_831 zxdsl_831cii
|
Cross-site scripting (XSS) vulnerability in the Quick Stats page (psilan.cgi) in ZTE ZXDSL 831 and 831CII allows remote attackers to inject arbitrary web script or HTML via the domainname parameter i…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9020
|
2024-11-21 11:20 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277815
|
- |
|
zte
|
zxdsl
|
Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin user name o…
|
CWE-352
Origin Validation Error
|
CVE-2014-9019
|
2024-11-21 11:20 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277816
|
- |
|
monstra
|
monstra
|
Monstra 3.0.1 and earlier uses a cookie to track how many login attempts have been attempted, which allows remote attackers to conduct brute force login attacks by deleting the login_attempts cookie …
|
CWE-255
Credentials Management
|
CVE-2014-9006
|
2024-11-21 11:20 |
2014-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277817
|
- |
|
vld_interactive
|
vldpersonals
|
Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL commands via the (1) country, (2) gender1, or ((3) gender2 parameter in a search ac…
|
CWE-89
SQL Injection
|
CVE-2014-9005
|
2024-11-21 11:20 |
2014-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277818
|
- |
|
vld_interactive
|
vldpersonals
|
Cross-site scripting (XSS) vulnerability in vldPersonals before 2.7.1 allows remote attackers to inject arbitrary web script or HTML via the id parameter in a member_profile action to index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2014-9004
|
2024-11-21 11:20 |
2014-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277819
|
- |
|
lantronix
|
xprintserver
|
Cross-site request forgery (CSRF) vulnerability in Lantronix xPrintServer allows remote attackers to hijack the authentication of administrators for requests that modify configuration, as demonstrate…
|
CWE-352
Origin Validation Error
|
CVE-2014-9003
|
2024-11-21 11:20 |
2014-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277820
|
- |
|
lantronix
|
xprintserver
|
Lantronix xPrintServer does not properly restrict access to ips/, which allows remote attackers to execute arbitrary commands via the c parameter in an rpc action.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9002
|
2024-11-21 11:20 |
2014-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|