|
279091
|
7.5 |
HIGH
Network
|
huawei
|
ac6605_firmware acu_firmware s_series_firmware s5300_firmware s5700_firmware s6700_firmware s6300_firmware s7700_firmware s9700_firmware s9300_firmware s9300e_firmware
|
Huawei AC6605 with software V200R001C00; AC6605 with software V200R002C00; ACU with software V200R001C00; ACU with software V200R002C00; S2300, S3300, S2700, S3700 with software V100R006C05 and earli…
|
CWE-20
Improper Input Validation
|
CVE-2014-8572
|
2024-11-21 11:19 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279092
|
3.3 |
LOW
Local
|
huawei
|
ascend_p6_edge-u00_firmware ascend_p6_edge-t00_firmware ascend_p6_edge-c00_firmware
|
Apps on Huawei Ascend P6 mobile phones with software EDGE-U00 V100R001C17B508SP01 and earlier versions before V100R001C17B508SP02; EDGE-T00 V100R001C01B508SP01 and earlier versions before V100R001C01…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8571
|
2024-11-21 11:19 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279093
|
5.3 |
MEDIUM
Network
|
huawei
|
s9300_firmware s9303_firmware s9306_firmware s9312_firmware s7700_firmware s7703_firmware s7706_firmware s7712_firmware s9300e_firmware s9303e_firmware s9306e_firmware
|
Huawei S9300, S9303, S9306, S9312 with software V100R002; S7700, S7703, S7706, S7712 with software V100R003, V100R006, V200R001, V200R002, V200R003, V200R005; S9300E, S9303E, S9306E, S9312E with soft…
|
CWE-200
Information Exposure
|
CVE-2014-8570
|
2024-11-21 11:19 |
2017-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279094
|
9.8 |
CRITICAL
Network
|
phpmemcachedadmin_project
|
phpmemcachedadmin
|
PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2014-8731
|
2024-11-21 11:19 |
2017-03-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279095
|
5.3 |
MEDIUM
Network
|
get-simple
|
getsimple_cms
|
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) plugins/anonymous_data.php or (2) plugins/InnovationPlugin.php, which reveals the installation …
|
CWE-200
Information Exposure
|
CVE-2014-8723
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279096
|
7.5 |
HIGH
Network
|
get-simple
|
getsimple_cms
|
GetSimple CMS 3.3.4 allows remote attackers to obtain sensitive information via a direct request to (1) data/users/<username>.xml, (2) backups/users/<username>.xml.bak, (3) data/other/authorization.x…
|
CWE-200
Information Exposure
|
CVE-2014-8722
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279097
|
9.8 |
CRITICAL
Network
|
pluck-cms
|
pluck
|
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8708
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279098
|
5.4 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
Cross-site scripting (XSS) vulnerability in TinyMCE in Pluck CMS 4.7.2 allows remote authenticated users to inject arbitrary web script or HTML via the "edit HTML source" option.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8707
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279099
|
5.3 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to …
|
CWE-200
Information Exposure
|
CVE-2014-8706
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279100
|
9.8 |
CRITICAL
Network
|
wondercms
|
wondercms
|
PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the hook parameter.
|
CWE-20
Improper Input Validation
|
CVE-2014-8705
|
2024-11-21 11:19 |
2017-03-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|