|
277431
|
5.9 |
MEDIUM
Network
|
mediawiki
|
mediawiki
|
The Scribunto extension for MediaWiki allows remote attackers to obtain the rollback token and possibly other sensitive information via a crafted module, related to unstripping special page HTML.
|
CWE-200
Information Exposure
|
CVE-2014-9481
|
2024-11-21 11:20 |
2020-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277432
|
6.1 |
MEDIUM
Network
|
clickdesk
|
clickdesk
|
ClickDesk version 4.3 and below has persistent cross site scripting
|
CWE-79
Cross-site Scripting
|
CVE-2014-9211
|
2024-11-21 11:20 |
2020-01-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277433
|
6.5 |
MEDIUM
Network
|
free
|
freebox_os
|
Freebox OS Web interface 3.0.2 has CSRF which can allow VPN user account creation
|
CWE-352
Origin Validation Error
|
CVE-2014-9382
|
2024-11-21 11:20 |
2020-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277434
|
5.4 |
MEDIUM
Network
|
free
|
freebox_os
|
A Cross-Site Scripting (XSS) vulnerability exists in the description field of an Download RSS item or Contacts in Freebox OS Web interface 3.0.2, which allows malicious users to execute arbitrary cod…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9405
|
2024-11-21 11:20 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277435
|
8.6 |
HIGH
Network
|
docker
|
docker
|
Path traversal vulnerability in Docker before 1.3.3 allows remote attackers to write to arbitrary files and bypass a container protection mechanism via a full pathname in a symlink in an (1) image or…
|
CWE-22
Path Traversal
|
CVE-2014-9356
|
2024-11-21 11:20 |
2019-12-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277436
|
4.3 |
MEDIUM
Network
|
wpmarketplace_project
|
wpmarketplace
|
Directory traversal vulnerability in the ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin before 2.4.1 for WordPress allows remote authenticated users to download arbitra…
|
CWE-22
Path Traversal
|
CVE-2014-9014
|
2024-11-21 11:20 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277437
|
8.8 |
HIGH
Network
|
wpmarketplace_project
|
wpmarketplace
|
The ajaxinit function in wpmarketplace/libs/cart.php in the WP Marketplace plugin 2.4.0 for WordPress allows remote authenticated users to create arbitrary users and gain admin privileges via a reque…
|
CWE-20
Improper Input Validation
|
CVE-2014-9013
|
2024-11-21 11:20 |
2019-11-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277438
|
9.8 |
CRITICAL
Network
|
honeywell
|
experion_process_knowledge_system
|
A file inclusion vulnerability exists in the confd.exe module in Honeywell Experion PKS R40x before R400.6, R41x before R410.6, and R43x before R430.2, which could lead to accepting an arbitrary file…
|
CWE-20
Improper Input Validation
|
CVE-2014-9186
|
2024-11-21 11:20 |
2019-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277439
|
9.8 |
CRITICAL
Network
|
honeywell
|
experion_process_knowledge_system
|
Multiple stack-based buffer overflow vulnerabilities were found in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules that cou…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9189
|
2024-11-21 11:20 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277440
|
9.8 |
CRITICAL
Network
|
honeywell
|
experion_process_knowledge_system
|
Multiple heap-based buffer overflow vulnerabilities exist in Honeywell Experion PKS all versions prior to R400.6, all versions prior to R410.6, and all versions prior to R430.2 modules, which could l…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2014-9187
|
2024-11-21 11:20 |
2019-03-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|