258391
|
- |
|
canonical
|
libpam-modules ubuntu_linux
|
Untrusted search path vulnerability in pam_motd (aka the MOTD module) in libpam-modules before 1.1.3-2ubuntu2.1 on Ubuntu 11.10, before 1.1.2-2ubuntu8.4 on Ubuntu 11.04, before 1.1.1-4ubuntu2.4 on Ub…
|
NVD-CWE-Other
|
CVE-2011-3628
|
2014-04-17 00:04 |
2014-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258392
|
- |
|
canonical
|
libpam-modules ubuntu_linux
|
Per: http://cwe.mitre.org/data/definitions/426.html
"CWE-426: Untrusted Search Path"
|
NVD-CWE-Other
|
CVE-2011-3628
|
2014-04-17 00:04 |
2014-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258393
|
- |
|
paperthin
|
commonspot_content_server
|
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code via shell metacharacters in an unspecified context.
|
CWE-78
OS Command
|
CVE-2014-2874
|
2014-04-16 23:47 |
2014-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258394
|
- |
|
paperthin
|
commonspot_content_server
|
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 does not require authentication for access to log files, which allows remote attackers to obtain sensitive server information by using a predict…
|
CWE-200
Information Exposure
|
CVE-2014-2873
|
2014-04-16 23:43 |
2014-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258395
|
- |
|
paperthin
|
commonspot_content_server
|
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain potentially sensitive information from a directory listing via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2014-2872
|
2014-04-16 23:41 |
2014-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258396
|
- |
|
paperthin
|
commonspot_content_server
|
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on an HTTP session for entering credentials on login pages, which allows remote attackers to obtain sensitive information by sniffing the…
|
CWE-200
Information Exposure
|
CVE-2014-2871
|
2014-04-16 23:40 |
2014-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258397
|
- |
|
paperthin
|
commonspot_content_server
|
The default configuration of PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 uses cleartext for storage of credentials in a database, which makes it easier for context-dependent attackers to o…
|
CWE-255
Credentials Management
|
CVE-2014-2870
|
2014-04-16 23:38 |
2014-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258398
|
- |
|
paperthin
|
commonspot_content_server
|
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to obtain sensitive information via requests to unspecified URIs, as demonstrated by pathname, SQL server, e-mail addres…
|
CWE-200
Information Exposure
|
CVE-2014-2869
|
2014-04-16 23:37 |
2014-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258399
|
- |
|
paperthin
|
commonspot_content_server
|
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to modify the flow of execution of ColdFusion code by using an HTTP GET request to set a ColdFusion variable.
|
NVD-CWE-Other
|
CVE-2014-2868
|
2014-04-16 23:35 |
2014-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258400
|
- |
|
paperthin
|
commonspot_content_server
|
Per http://cwe.mitre.org/data/definitions/472.html "CWE-472: External Control of Assumed-Immutable Web Parameter"
|
NVD-CWE-Other
|
CVE-2014-2868
|
2014-04-16 23:35 |
2014-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|