|
279361
|
- |
|
vbulletin
|
vbulletin
|
Open redirect vulnerability in go.php in vBulletin 4.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter.
|
NVD-CWE-Other
|
CVE-2014-8670
|
2024-11-21 11:19 |
2014-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279362
|
- |
|
sap
|
customer_relationship_management
|
The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2014-8669
|
2024-11-21 11:19 |
2014-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279363
|
- |
|
sap
|
contract_accounting
|
SQL injection vulnerability in SAP Contract Accounting allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2014-8668
|
2024-11-21 11:19 |
2014-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279364
|
- |
|
sap
|
hana_web-based_development_workbench
|
Cross-site scripting (XSS) vulnerability in SAP HANA Web-based Development Workbench allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8667
|
2024-11-21 11:19 |
2014-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279365
|
- |
|
sap
|
business_intelligence_development_workbench
|
The User & Server configuration, InfoView refresh, user rights (BI-BIP-ADM) component in SAP Business Intellignece allows remote attackers to obtain audit event details via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2014-8666
|
2024-11-21 11:19 |
2014-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279366
|
- |
|
sap
|
business_intelligence_development_workbench
|
The SAP Business Intelligence Development Workbench allows remote attackers to obtain sensitive information by reading unspecified files.
|
CWE-200
Information Exposure
|
CVE-2014-8665
|
2024-11-21 11:19 |
2014-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279367
|
- |
|
sap
|
environment_health_and_safety
|
SQL injection vulnerability in Product Safety (EHS-SAF) component in SAP Environment, Health, and Safety Management allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2014-8664
|
2024-11-21 11:19 |
2014-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279368
|
- |
|
sap
|
netweaver_business_warehouse
|
SQL injection vulnerability in Data Basis (BW-WHM-DBA) in SAP NetWeaver Business Warehouse allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2014-8663
|
2024-11-21 11:19 |
2014-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279369
|
- |
|
sap
|
payroll_process
|
Unspecified vulnerability in SAP Payroll Process allows remote attackers to cause a denial of service via vectors related to session handling.
|
NVD-CWE-noinfo
|
CVE-2014-8662
|
2024-11-21 11:19 |
2014-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279370
|
- |
|
sap
|
customer_relationship_management_internet_sales
|
The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2014-8661
|
2024-11-21 11:19 |
2014-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|