|
279021
|
- |
|
ubercart
|
ubercart
|
The Ubercart module 7.x-3.x before 7.x-3.7 for Drupal does not properly protect the per-user order history view, which allows remote authenticated users with the "view own orders" permission to obtai…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9026
|
2024-11-21 11:20 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279022
|
- |
|
commerceguys
|
commerce
|
The default checkout completion rule in the commerce_order module in the Drupal Commerce module 7.x-1.x before 7.x-1.10 for Drupal uses the email address as the username for new accounts created at c…
|
CWE-200
Information Exposure
|
CVE-2014-9025
|
2024-11-21 11:20 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279023
|
- |
|
protected_pages_project
|
protected_pages
|
The Protected Pages module 7.x-2.x before 7.x-2.4 for Drupal allows remote attackers to bypass the password protection via a crafted path.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9024
|
2024-11-21 11:20 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279024
|
- |
|
twilio_project
|
twilio
|
The Twilio module 7.x-1.x before 7.x-1.9 for Drupal does not properly restrict access to the Twilio administration pages, which allows remote authenticated users to read and modify authentication tok…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9023
|
2024-11-21 11:20 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279025
|
- |
|
web_component_roles_project
|
web_component_roles
|
The Webform Component Roles module 6.x-1.x before 6.x-1.8 and 7.x-1.x before 7.x-1.8 for Drupal allows remote attackers to bypass the "disabled" restriction and modify read-only components via a craf…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-9022
|
2024-11-21 11:20 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279026
|
- |
|
zteusa
|
zxdsl_831
|
Multiple cross-site scripting (XSS) vulnerabilities in ZTE ZXDSL 831 allow remote attackers to inject arbitrary web script or HTML via the (1) tr69cAcsURL, (2) tr69cAcsUser, (3) tr69cAcsPwd, (4) tr69…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9021
|
2024-11-21 11:20 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279027
|
- |
|
zte
|
zxdsl_831 zxdsl_831cii
|
Cross-site scripting (XSS) vulnerability in the Quick Stats page (psilan.cgi) in ZTE ZXDSL 831 and 831CII allows remote attackers to inject arbitrary web script or HTML via the domainname parameter i…
|
CWE-79
Cross-site Scripting
|
CVE-2014-9020
|
2024-11-21 11:20 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279028
|
- |
|
zte
|
zxdsl
|
Multiple cross-site request forgery (CSRF) vulnerabilities in ZTE ZXDSL 831CII allow remote attackers to hijack the authentication of administrators for requests that (1) change the admin user name o…
|
CWE-352
Origin Validation Error
|
CVE-2014-9019
|
2024-11-21 11:20 |
2014-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279029
|
- |
|
monstra
|
monstra
|
Monstra 3.0.1 and earlier uses a cookie to track how many login attempts have been attempted, which allows remote attackers to conduct brute force login attacks by deleting the login_attempts cookie …
|
CWE-255
Credentials Management
|
CVE-2014-9006
|
2024-11-21 11:20 |
2014-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279030
|
- |
|
vld_interactive
|
vldpersonals
|
Multiple SQL injection vulnerabilities in vldPersonals before 2.7.1 allow remote attackers to execute arbitrary SQL commands via the (1) country, (2) gender1, or ((3) gender2 parameter in a search ac…
|
CWE-89
SQL Injection
|
CVE-2014-9005
|
2024-11-21 11:20 |
2014-11-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|