257761
|
- |
|
tom_m8te_plugin_project
|
tom-m8te_plugin
|
Directory traversal vulnerability in the Tom M8te (tom-m8te) plugin 1.5.3 for WordPress allows remote attackers to read arbitrary files via the file parameter to tom-download-file.php.
|
CWE-22
Path Traversal
|
CVE-2014-5187
|
2014-08-7 22:25 |
2014-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257762
|
- |
|
all_video_gallery_plugin_project
|
all-video-gallery
|
SQL injection vulnerability in the All Video Gallery (all-video-gallery) plugin 1.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in …
|
CWE-89
SQL Injection
|
CVE-2014-5186
|
2014-08-7 22:22 |
2014-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257763
|
- |
|
quartz_plugin_project
|
quartz_plugin
|
SQL injection vulnerability in the Quartz plugin 1.01.1 for WordPress allows remote authenticated users with Contributor privileges to execute arbitrary SQL commands via the quote parameter in an edi…
|
CWE-89
SQL Injection
|
CVE-2014-5185
|
2014-08-7 22:14 |
2014-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257764
|
- |
|
stripshow_plugin_project
|
stripshow
|
SQL injection vulnerability in the stripshow-storylines page in the stripShow plugin 2.5.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the story par…
|
CWE-89
SQL Injection
|
CVE-2014-5184
|
2014-08-7 22:06 |
2014-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257765
|
- |
|
ostenta
|
yawpp
|
Multiple SQL injection vulnerabilities in the yawpp plugin 1.2 for WordPress allow remote authenticated users with Contributor privileges to execute arbitrary SQL commands via vectors related to (1) …
|
CWE-89
SQL Injection
|
CVE-2014-5182
|
2014-08-7 21:46 |
2014-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257766
|
- |
|
last.fm_rotation_plugin_project
|
lastfm-rotation_plugin
|
Directory traversal vulnerability in lastfm-proxy.php in the Last.fm Rotation (lastfm-rotation) plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the snod…
|
CWE-22
Path Traversal
|
CVE-2014-5181
|
2014-08-7 21:42 |
2014-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257767
|
- |
|
hdwplayer
|
hdw-player-video-player-video-gallery
|
SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL…
|
CWE-89
SQL Injection
|
CVE-2014-5180
|
2014-08-7 21:30 |
2014-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257768
|
- |
|
all_video_gallery_plugin_project
|
all_video_gallery_plugin
|
Unspecified vulnerability in the All Video Gallery (all-video-gallery) plugin before 1.2.0 for WordPress has unspecified impact and attack vectors.
|
NVD-CWE-noinfo
|
CVE-2012-6653
|
2014-08-7 21:25 |
2014-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257769
|
- |
|
status2k
|
status2k
|
admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel.
|
CWE-94
Code Injection
|
CVE-2014-5090
|
2014-08-7 21:13 |
2014-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257770
|
- |
|
status2k
|
status2k
|
SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter.
|
CWE-89
SQL Injection
|
CVE-2014-5089
|
2014-08-7 21:12 |
2014-08-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|