Latest CVE Feed
-
4.3
MEDIUMCVE-2014-9243
Multiple cross-site scripting (XSS) vulnerabilities in WebsiteBaker 2.8.3 allow remote attackers to inject arbitrary web script or HTML via the (1) QUERY_STRING to wb/admin/admintools/tool.php or (2) section_id parameter to edit_module_files.php, (3) news... Read more
Affected Products : websitebaker- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9242
SQL injection vulnerability in admin/pages/modify.php in WebsiteBaker 2.8.3 allows remote attackers to execute arbitrary SQL commands via the page_id parameter.... Read more
Affected Products : websitebaker- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9241
Multiple cross-site scripting (XSS) vulnerabilities in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allow remote attackers to inject arbitrary web script or HTML via the (1) type parameter to report.php, (2) signature parameter in a do_editsig action to ... Read more
Affected Products : mybb- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9240
SQL injection vulnerability in member.php in MyBB (aka MyBulletinBoard) 1.8.x before 1.8.2 allows remote attackers to execute arbitrary SQL commands via the question_id parameter in a do_register action.... Read more
Affected Products : mybb- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9239
SQL injection vulnerability in the IPS Connect service (interface/ipsconnect/ipsconnect.php) in Invision Power Board (aka IPB or IP.Board) 3.3.x and 3.4.x through 3.4.7 before 20141114 allows remote attackers to execute arbitrary SQL commands via the id[]... Read more
- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9238
D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to obtain the installation path via the file parameter to cgi-bin/sddownload.cgi, as demonstrated by a / (forward slash) character.... Read more
- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9237
SQL injection vulnerability in Proticaret E-Commerce 3.0 allows remote attackers to execute arbitrary SQL commands via a tem:Code element in a SOAP request.... Read more
Affected Products : proticaret- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-9236
Cross-site scripting (XSS) vulnerability in php/edit_photos.php in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the (1) photographer_id or (2) _crumb parameter.... Read more
Affected Products : zoph- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2014-9235
Multiple SQL injection vulnerabilities in Zoph (aka Zoph Organizes Photos) 0.9.1 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) _action parameter to group.php or (2) user.php or the (3) location_id parameter to ... Read more
Affected Products : zoph- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9234
Directory traversal vulnerability in cgi-bin/sddownload.cgi in D-link IP camera DCS-2103 with firmware 1.0.0 allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.... Read more
- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2014-9157
Format string vulnerability in the yyerror function in lib/cgraph/scan.l in Graphviz allows remote attackers to have unspecified impact via format string specifiers in unknown vectors, which are not properly handled in an error string.... Read more
- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-9134
Unrestricted file upload vulnerability in Huawei Honor Cube Wireless Router WS860s before V100R001C02B222 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via unspecified vectors.... Read more
- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2013-7416
canto_curses/guibase.py in Canto Curses before 0.9.0 allows remote feed servers to execute arbitrary commands via shell metacharacters in a URL in a feed.... Read more
Affected Products : canto_curses- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-9018
Icecast before 2.4.1 transmits the output of the on-connect script, which might allow remote attackers to obtain sensitive information, related to shared file descriptors.... Read more
Affected Products : icecast- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
5.0
MEDIUMCVE-2014-8775
MODX Revolution 2.x before 2.2.15 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.... Read more
Affected Products : modx_revolution- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2014-8774
Cross-site scripting (XSS) vulnerability in manager/index.php in MODX Revolution 2.x before 2.2.15 allows remote attackers to inject arbitrary web script or HTML via the context_key parameter.... Read more
Affected Products : modx_revolution- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-8773
MODX Revolution 2.x before 2.2.15 allows remote attackers to bypass the cross-site request forgery (CSRF) protection mechanism by (1) omitting the CSRF token or via a (2) long string in the CSRF token parameter.... Read more
Affected Products : modx_revolution- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
3.5
LOWCVE-2014-8772
Cross-site scripting (XSS) vulnerability in the search_controller in X3 CMS 0.5.1 and 0.5.1.1 allows remote authenticated users to inject arbitrary web script or HTML via the search parameter.... Read more
Affected Products : x3_cms- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-8771
Multiple cross-site request forgery (CSRF) vulnerabilities in the admin area in X3 CMS 0.5.1 and 0.5.1.1 allow remote attackers to hijack the authentication of administrators via unspecified vectors.... Read more
Affected Products : x3_cms- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025
-
6.8
MEDIUMCVE-2014-8104
OpenVPN 2.x before 2.0.11, 2.1.x, 2.2.x before 2.2.3, and 2.3.x before 2.3.6 allows remote authenticated users to cause a denial of service (server crash) via a small control channel packet.... Read more
- Published: Dec. 03, 2014
- Modified: Apr. 12, 2025