Latest CVE Feed
-
4.3
MEDIUMCVE-2014-9142
Cross-site scripting (XSS) vulnerability in Technicolor Router TD5130 with firmware 2.05.C29GV allows remote attackers to inject arbitrary web script or HTML via the failrefer parameter.... Read more
Affected Products : td5130_router_firmware- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-9129
Cross-site request forgery (CSRF) vulnerability in the CreativeMinds CM Downloads Manager plugin before 2.0.7 for WordPress allows remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks... Read more
- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8800
Cross-site scripting (XSS) vulnerability in nextend-facebook-settings.php in the Nextend Facebook Connect plugin before 1.5.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the fb_login_button parameter in a newfb_update_... Read more
Affected Products : nextend_facebook_connect- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3997
SQL injection vulnerability in the MetadataServlet servlet in ManageEngine Password Manager Pro (PMP) and Password Manager Pro Managed Service Providers (MSP) edition 5 through 7 build 7003, IT360 and IT360 Managed Service Providers (MSP) edition before 1... Read more
- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-3996
SQL injection vulnerability in the LinkViewFetchServlet servlet in ManageEngine Desktop Central (DC) and Desktop Central Managed Service Providers (MSP) edition before 9 build 90043, Password Manager Pro (PMP) and Password Manager Pro Managed Service Prov... Read more
- Published: Dec. 05, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-7868
Multiple SQL injection vulnerabilities in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allow remote attackers or remote authenticated users to execute arbitrary SQL commands via the (1) OPM_BVNAME parameter in a ... Read more
- Published: Dec. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-7867
SQL injection vulnerability in the com.manageengine.opmanager.servlet.UpdateProbeUpgradeStatus servlet in ZOHO ManageEngine OpManager 11.3 and 11.4, IT360 10.3 and 10.4, and Social IT Plus 11.0 allows remote attackers or remote authenticated users to exec... Read more
- Published: Dec. 04, 2014
- Modified: Apr. 12, 2025
-
6.4
MEDIUMCVE-2014-6036
Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via a... Read more
- Published: Dec. 04, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-6035
Directory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier allows remote attackers to write and execute arbitrary files via a .. (dot dot) in the FILENAME parameter.... Read more
Affected Products : manageengine_opmanager- Published: Dec. 04, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-6034
Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.8 through 11.3, Social IT Plus 11.0, and IT360 10.4 and earlier allows remote attackers or remote authenti... Read more
- Published: Dec. 04, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-5446
Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote attackers and remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parame... Read more
- Published: Dec. 04, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-5445
Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remote authenticated users to read arbitrary files via a full pathname in the schFilePath parameter to the (1)... Read more
- Published: Dec. 04, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9243
Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) QUERY_STRING to wb/admin/admintools/tool.php or (2) section_id parameter to edit_module_files.php, (3) news... Read more
Affected Products : websitebaker- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9242
SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.... Read more
Affected Products : websitebaker- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9241
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) type parameter to report.php, (2) signature parameter in a do_editsig action to ... Read more
Affected Products : mybb- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9240
SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the question_id parameter in a do_register action.... Read more
Affected Products : mybb- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9239
SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and 3.4.x through 3.4.7 before 20141114 allows remote attackers to execute arbitrary SQL commands via the id[]... Read more
- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9238
D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to obtain the installation path via the file parameter to cgi-bin/sddownload.cgi, as demonstrated by a / (forward slash) character.... Read more
- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9237
SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a tem:Code element in a SOAP request.... Read more
Affected Products : proticaret- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9236
Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) photographer_id or (2) _crumb parameter.... Read more
Affected Products : zoph- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025