Latest CVE Feed
-
6.4
MEDIUMCVE-2011-5290
The SaveToFile method in the UniBasicPack.UniTextBox ActiveX control in UniBasic100_EDA1811C.ocx in IDrive Online Backup 3.4.0 allows remote attackers to write to arbitrary files via a pathname in the first argument.... Read more
Affected Products : idrive_online_backup- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2011-5289
The SaveDecrypted method in the ChilkatCrypt2.ChilkatOmaDrm.1 ActiveX control in ChilkatCrypt2.dll in aTube Catcher 2.3.570 allows remote attackers to write to arbitrary files via a pathname in the argument.... Read more
Affected Products : atube_catcher- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2011-5288
Multiple buffer overflows in the ThreeDify.ThreeDifyDesigner.1 ActiveX control in ActiveSolid.dll in ThreeDify Designer 5.0.2 allow remote attackers to execute arbitrary code via a long argument to the (1) cmdExport, (2) cmdImport, (3) cmdOpen, or (4) cmd... Read more
Affected Products : threedify_designer- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-5287
Multiple cross-site scripting (XSS) vulnerabilities in HESK before 2.4.1 allow remote attackers to inject arbitrary web script or HTML via the (1) hesk_settings[tmp_title] or (2) hesklang[ENCODING] parameter to inc/header.inc.php; the hesklang[attempt] pa... Read more
Affected Products : hesk- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2011-5286
SQL injection vulnerability in social-slider-2/ajax.php in the Social Slider plugin before 7.4.2 for WordPress allows remote attackers to execute arbitrary SQL commands via the rA array parameter.... Read more
Affected Products : social_slider- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-5285
Multiple cross-site scripting (XSS) vulnerabilities in BugFree 2.1.3 allow remote attackers to inject arbitrary web script or HTML via (1) the ActionType parameter to Bug.php, the ReportMode parameter to (2) Report.php or (3) ReportLeft.php, or the PATH_I... Read more
Affected Products : bugfree- Published: Jan. 01, 2015
- Modified: Apr. 12, 2025
-
2.6
LOWCVE-2014-9433
Multiple cross-site scripting (XSS) vulnerabilities in cms/front_content.php in Contenido before 4.9.6, when advanced mod rewrite (AMR) is disabled, allow remote attackers to inject arbitrary web script or HTML via the (1) idart, (2) lang, or (3) idcat pa... Read more
Affected Products : contendio- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9432
Multiple cross-site scripting (XSS) vulnerabilities in templates/2k11/admin/overview.inc.tpl in Serendipity before 2.0-rc2 allow remote attackers to inject arbitrary web script or HTML via a blog comment in the QUERY_STRING to serendipity/index.php.... Read more
Affected Products : serendipity- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9431
Multiple cross-site request forgery (CSRF) vulnerabilities in Smoothwall Express 3.1 and 3.0 SP3 allow remote attackers to hijack the authentication of administrators for requests that change the (1) admin or (2) dial password via a request to httpd/cgi-b... Read more
Affected Products : smoothwall- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9430
Cross-site scripting (XSS) vulnerability in httpd/cgi-bin/vpn.cgi/vpnconfig.dat in Smoothwall Express 3.0 SP3 allows remote attackers to inject arbitrary web script or HTML via the COMMENT parameter in an Add action.... Read more
Affected Products : smoothwall- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9429
Multiple cross-site scripting (XSS) vulnerabilities in Smoothwall Express 3.1 and 3.0 SP3 allow remote attackers to inject arbitrary web script or HTML via the (1) PROFILENAME parameter in a Save action to httpd/cgi-bin/pppsetup.cgi or (2) COMMENT paramet... Read more
Affected Products : smoothwall- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9119
Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.... Read more
Affected Products : db_backup- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-8145
Multiple heap-based buffer overflows in Sound eXchange (SoX) 14.4.1 and earlier allow remote attackers to have unspecified impact via a crafted WAV file to the (1) start_read or (2) AdpcmReadBlock function.... Read more
- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-8144
Cross-site request forgery (CSRF) vulnerability in doorkeeper before 1.4.1 allows remote attackers to hijack the authentication of unspecified victims for requests that read a user OAuth authorization code via unknown vectors.... Read more
Affected Products : doorkeeper- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2011-5284
Cross-site request forgery (CSRF) vulnerability in the web management interface in httpd/cgi-bin/shutdown.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to hijack the authentication of administrators for requests that perfor... Read more
Affected Products : smoothwall- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2011-5283
Cross-site scripting (XSS) vulnerability in the web management interface in httpd/cgi-bin/ipinfo.cgi in Smoothwall Express 3.1 and 3.0 SP3 and earlier allows remote attackers to inject arbitrary web script or HTML via the IP parameter in a Run action.... Read more
Affected Products : smoothwall- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9401
Cross-site request forgery (CSRF) vulnerability in the WP Limit Posts Automatically plugin 0.7 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks vi... Read more
Affected Products : wp_limit_posts_automatically- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9400
Multiple cross-site request forgery (CSRF) vulnerabilities in the Wp Unique Article Header Image plugin 1.0 and earlier for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS... Read more
Affected Products : wp_unique_article_header_image- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9399
Cross-site request forgery (CSRF) vulnerability in the TweetScribe plugin 1.1 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the tweetscribe... Read more
Affected Products : tweetscribe- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9398
Cross-site request forgery (CSRF) vulnerability in the Twitter LiveBlog plugin 1.1.2 and earlier for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the mash... Read more
Affected Products : twitter_liveblog- Published: Dec. 31, 2014
- Modified: Apr. 12, 2025