258311
|
- |
|
mediawiki
|
mediawiki
|
The zend_inline_hash_func function in php-luasandbox in the Scribuntu extension for MediaWiki before 1.19.10, 1.2x before 1.21.4, and 1.22.x before 1.22.1 allows remote attackers to cause a denial of…
|
NVD-CWE-Other
|
CVE-2013-4570
|
2014-05-13 01:13 |
2014-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258312
|
- |
|
mediawiki
|
mediawiki
|
Per: http://cwe.mitre.org/data/definitions/476.html
"CWE-476: NULL Pointer Dereference"
|
NVD-CWE-Other
|
CVE-2013-4570
|
2014-05-13 01:13 |
2014-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258313
|
- |
|
herry
|
sfpagent
|
lib/sfpagent/bsig.rb in the sfpagent gem before 0.4.15 for Ruby allows remote attackers to execute arbitrary commands via shell metacharacters in the module name in a JSON request.
|
NVD-CWE-Other
|
CVE-2014-2888
|
2014-05-10 13:06 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258314
|
- |
|
herry
|
sfpagent
|
Per: https://cwe.mitre.org/data/definitions/77.html
"CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection')"
|
NVD-CWE-Other
|
CVE-2014-2888
|
2014-05-10 13:06 |
2014-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258315
|
- |
|
sap
|
netweaver_software_lifecycle_manager
|
The Java Server Pages in the Software Lifecycle Manager (SLM) in SAP NetWeaver allows remote attackers to obtain sensitive information via a crafted request, related to SAP Solution Manager 7.1.
|
CWE-200
Information Exposure
|
CVE-2014-3129
|
2014-05-10 13:06 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258316
|
- |
|
sap
|
netweaver_abap_application_server
|
The ABAP Help documentation and translation tools (BC-DOC-HLP) in Basis in SAP Netweaver ABAP Application Server does not properly restrict access, which allows local users to gain privileges and exe…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3130
|
2014-05-10 13:06 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258317
|
- |
|
sap
|
profile_maintenance
|
SAP Profile Maintenance does not properly restrict access, which allows remote authenticated users to obtain sensitive information via an unspecified RFC function, related to SAP Solution Manager 7.1.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3131
|
2014-05-10 13:06 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258318
|
- |
|
sap
|
background_processing
|
SAP Background Processing does not properly restrict access, which allows remote authenticated users to obtain sensitive information via an unspecified RFC function, related to SAP Solution Manager 7…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3132
|
2014-05-10 13:06 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258319
|
- |
|
sap
|
netweaver_java_application_server
|
SAP Netweaver Java Application Server does not properly restrict access, which allows remote attackers to obtain the list of SAP systems registered on an SLD via an unspecified webdynpro, related to …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-3133
|
2014-05-10 13:06 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258320
|
- |
|
sap
|
businessobjects
|
Cross-site scripting (XSS) vulnerability in the InfoView application in SAP BusinessObjects allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2014-3134
|
2014-05-10 13:06 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|