|
281631
|
- |
|
cisco
|
webex_meetings_server
|
The play/modules component in Cisco WebEx Meetings Server allows remote attackers to obtain administrator access via crafted API requests, aka Bug ID CSCuj40421.
|
CWE-287
Improper Authentication
|
CVE-2014-8033
|
2024-11-21 11:18 |
2015-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281632
|
- |
|
cisco
|
webex_meetings_server
|
The OutlookAction LI in Cisco WebEx Meetings Server allows remote authenticated users to obtain sensitive encrypted-password information via unspecified vectors, aka Bug IDs CSCuj40453 and CSCuj40449.
|
CWE-200
Information Exposure
|
CVE-2014-8032
|
2024-11-21 11:18 |
2015-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281633
|
- |
|
cisco
|
webex_meetings_server
|
Cross-site request forgery (CSRF) vulnerability in Cisco WebEx Meetings Server allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuj40456.
|
CWE-352
Origin Validation Error
|
CVE-2014-8031
|
2024-11-21 11:18 |
2015-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281634
|
- |
|
cisco
|
webex_meetings_server
|
Cross-site scripting (XSS) vulnerability in sendPwMail.do in Cisco WebEx Meetings Server allows remote attackers to inject arbitrary web script or HTML via the email parameter, aka Bug ID CSCuj40381.
|
CWE-79
Cross-site Scripting
|
CVE-2014-8030
|
2024-11-21 11:18 |
2015-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281635
|
- |
|
cisco
|
secure_access_control_system
|
Open redirect vulnerability in the web interface in Cisco Secure Access Control System (ACS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via an unspe…
|
NVD-CWE-Other
|
CVE-2014-8029
|
2024-11-21 11:18 |
2015-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281636
|
- |
|
cisco
|
secure_access_control_system
|
Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Secure Access Control System (ACS) allow remote attackers to inject arbitrary web script or HTML via unspecified para…
|
CWE-79
Cross-site Scripting
|
CVE-2014-8028
|
2024-11-21 11:18 |
2015-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281637
|
- |
|
cisco
|
secure_access_control_system
|
The RBAC component in Cisco Secure Access Control System (ACS) allows remote authenticated users to obtain Network Device Administrator privileges for Create, Delete, Read, and Update operations via …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8027
|
2024-11-21 11:18 |
2015-01-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281638
|
- |
|
redhat
|
libvirt
|
The qemu implementation of virConnectGetAllDomainStats in libvirt before 1.2.11 does not properly handle locks when a domain is skipped due to ACL restrictions, which allows a remote authenticated us…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-8131
|
2024-11-21 11:18 |
2015-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281639
|
- |
|
osclass
|
osclass
|
Unrestricted file upload vulnerability in the CWebContact::doModel method in oc-includes/osclass/controller/contact.php in OSClass before 3.4.3 allows remote attackers to execute arbitrary PHP code b…
|
NVD-CWE-Other
|
CVE-2014-8085
|
2024-11-21 11:18 |
2015-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281640
|
- |
|
osclass
|
osclass
|
Directory traversal vulnerability in oc-includes/osclass/controller/ajax.php in OSClass before 3.4.3 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the aja…
|
CWE-22
Path Traversal
|
CVE-2014-8084
|
2024-11-21 11:18 |
2015-01-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|