257761
|
- |
|
gurock
|
testrail
|
Cross-site scripting (XSS) vulnerability in Gurock TestRail before 3.1.3 allows remote attackers to inject arbitrary web script or HTML via the Created By field in a project activity.
|
CWE-79
Cross-site Scripting
|
CVE-2014-4857
|
2014-07-29 04:05 |
2014-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257762
|
- |
|
caucho
|
resin
|
The ISO-8859-1 encoder in Resin Pro before 4.0.40 does not properly perform Unicode transformations, which allows remote attackers to bypass intended text restrictions via crafted characters, as demo…
|
CWE-264 CWE-20
Permissions, Privileges, and Access Controls Improper Input Validation
|
CVE-2014-2966
|
2014-07-29 04:00 |
2014-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257763
|
- |
|
morpho
|
itemiser_3
|
Morpho Itemiser 3 8.17 has hardcoded administrative credentials, which makes it easier for remote attackers to obtain access via a login request.
|
NVD-CWE-Other
|
CVE-2014-2363
|
2014-07-29 02:45 |
2014-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257764
|
- |
|
morpho
|
itemiser_3
|
<a href="http://cwe.mitre.org/data/definitions/798.html" target="_blank">CWE-798: Use of Hard-coded Credentials</a>
|
NVD-CWE-Other
|
CVE-2014-2363
|
2014-07-29 02:45 |
2014-07-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257765
|
- |
|
siemens
|
simatic_pcs7 wincc
|
The Project administration application in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, has a hardcoded encryption key, which allows remote attackers to obtain sensitive infor…
|
NVD-CWE-Other
|
CVE-2014-4686
|
2014-07-25 23:59 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257766
|
- |
|
siemens
|
simatic_pcs7 wincc
|
<a href="http://cwe.mitre.org/data/definitions/798.html" target="_blank">CWE-798: CWE-798: Use of Hard-coded Credentials</a>
|
NVD-CWE-Other
|
CVE-2014-4686
|
2014-07-25 23:59 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257767
|
- |
|
siemens
|
simatic_pcs7 wincc
|
Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows local users to gain privileges by leveraging weak system-object access control.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4685
|
2014-07-25 23:49 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257768
|
- |
|
siemens
|
simatic_pcs7 wincc
|
The database server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a request to TCP port 1433.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4684
|
2014-07-25 23:42 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257769
|
- |
|
siemens
|
simatic_pcs7 wincc
|
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote authenticated users to gain privileges via a (1) HTTP or (2) HTTPS request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-4683
|
2014-07-25 23:37 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257770
|
- |
|
siemens
|
simatic_pcs7 wincc
|
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive information via an HTTP request.
|
CWE-200
Information Exposure
|
CVE-2014-4682
|
2014-07-25 23:27 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|