258661
|
- |
|
plone
|
plone
|
Multiple cross-site scripting (XSS) vulnerabilities in (1) spamProtect.py, (2) pts.py, and (3) request.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote attackers…
|
CWE-79
Cross-site Scripting
|
CVE-2013-4190
|
2014-03-12 10:06 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258662
|
- |
|
plone
|
plone
|
Multiple unspecified vulnerabilities in (1) dataitems.py, (2) get.py, and (3) traverseName.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allow remote authenticated users w…
|
NVD-CWE-noinfo
|
CVE-2013-4189
|
2014-03-12 10:02 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258663
|
- |
|
plone
|
plone
|
traverser.py in Plone 2.1 through 4.1, 4.2.x through 4.2.5, and 4.3.x through 4.3.1 allows remote attackers with administrator privileges to cause a denial of service (infinite loop and resource cons…
|
CWE-399
Resource Management Errors
|
CVE-2013-4188
|
2014-03-12 09:59 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258664
|
- |
|
umi-cms
|
umi.cms
|
Cross-site request forgery (CSRF) vulnerability in Umisoft UMI.CMS before 2.9 build 21905 allows remote attackers to hijack the authentication of administrators for requests that add administrator ac…
|
CWE-352
Origin Validation Error
|
CVE-2013-2754
|
2014-03-12 09:47 |
2014-03-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258665
|
- |
|
catfish_project
|
catfish
|
Untrusted search path vulnerability in Catfish through 0.4.0.3 allows local users to gain privileges via a Trojan horse catfish.py in the current working directory.
|
NVD-CWE-Other
|
CVE-2014-2093
|
2014-03-12 01:57 |
2014-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258666
|
- |
|
catfish_project
|
catfish
|
Per: http://cwe.mitre.org/data/definitions/426.html
"CWE-426: Untrusted Search Path"
|
NVD-CWE-Other
|
CVE-2014-2093
|
2014-03-12 01:57 |
2014-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258667
|
- |
|
catfish_project
|
catfish
|
Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0 allows local users to gain privileges via a Trojan horse bin/catfish.py under the current working directory.
|
NVD-CWE-Other
|
CVE-2014-2096
|
2014-03-12 01:57 |
2014-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258668
|
- |
|
catfish_project
|
catfish
|
Per: http://cwe.mitre.org/data/definitions/426.html
"CWE-426: Untrusted Search Path"
|
NVD-CWE-Other
|
CVE-2014-2096
|
2014-03-12 01:57 |
2014-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258669
|
- |
|
catfish_project
|
catfish
|
Untrusted search path vulnerability in Catfish 0.6.0 through 1.0.0, when a Fedora package such as 0.8.2-1 is not used, allows local users to gain privileges via a Trojan horse bin/catfish.pyc under t…
|
NVD-CWE-Other
|
CVE-2014-2095
|
2014-03-12 01:56 |
2014-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258670
|
- |
|
catfish_project
|
catfish
|
Per: http://cwe.mitre.org/data/definitions/426.html
"CWE-426: Untrusted Search Path"
|
NVD-CWE-Other
|
CVE-2014-2095
|
2014-03-12 01:56 |
2014-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|