257941
|
- |
|
jo_hasenau
|
gridelements
|
Cross-site scripting (XSS) vulnerability in the layout wizard in the Grid Elements (gridelements) extension before 1.5.1 and 2.0.x before 2.0.3 for TYPO3 allows remote authenticated backend users to …
|
CWE-79
Cross-site Scripting
|
CVE-2014-3949
|
2014-06-6 02:32 |
2014-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257942
|
- |
|
owncloud
|
owncloud
|
ownCloud Server before 4.5.7 does not properly check ownership of calendars, which allows remote authenticated users to read arbitrary calendars via the calid parameter to /apps/calendar/export.php. …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2013-0304
|
2014-06-6 02:28 |
2014-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257943
|
- |
|
opennms
|
opennms
|
Multiple cross-site scripting (XSS) vulnerabilities in OpenNMS before 1.12.7 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-3960
|
2014-06-5 22:30 |
2014-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257944
|
- |
|
cogentdatahub
|
cogent_datahub
|
Directory traversal vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to read arbitrary files of unspecified types, or cause a web-server denial of service, via a crafted pathname.
|
CWE-22
Path Traversal
|
CVE-2014-2352
|
2014-06-5 21:49 |
2014-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257945
|
- |
|
cogentdatahub
|
cogent_datahub
|
Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.
|
CWE-255
Credentials Management
|
CVE-2014-2354
|
2014-06-5 21:40 |
2014-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257946
|
- |
|
cogentdatahub
|
cogent_datahub
|
Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-2353
|
2014-06-5 21:36 |
2014-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257947
|
- |
|
trianglemicroworks
|
scada_data_gateway
|
Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows remote attackers to cause a denial of service (excessive data processing) via a crafted DNP3 packet.
|
CWE-20
Improper Input Validation
|
CVE-2014-2342
|
2014-06-5 21:32 |
2014-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257948
|
- |
|
owncloud
|
owncloud
|
ownCloud Server before 5.0.16 and 6.0.x before 6.0.3 does not check permissions to the files_external application, which allows remote authenticated users to add external storage via unspecified vect…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3835
|
2014-06-5 20:10 |
2014-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257949
|
- |
|
postfix_admin_project
|
postfix_admin
|
SQL injection vulnerability in the gen_show_status function in functions.inc.php in Postfix Admin (aka postfixadmin) before 2.3.7 allows remote authenticated users to execute arbitrary SQL commands v…
|
CWE-89
SQL Injection
|
CVE-2014-2655
|
2014-06-5 13:31 |
2014-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257950
|
- |
|
debian
|
dpkg
|
dpkg 1.15.9 on Debian squeeze introduces support for the "C-style encoded filenames" feature without recognizing that the squeeze patch program lacks this feature, which triggers an interaction error…
|
CWE-22
Path Traversal
|
CVE-2014-3127
|
2014-06-5 13:31 |
2014-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|