257811
|
- |
|
siemens
|
simatic_pcs7 wincc
|
The WebNavigator server in Siemens SIMATIC WinCC before 7.3, as used in PCS7 and other products, allows remote attackers to obtain sensitive information via an HTTP request.
|
CWE-200
Information Exposure
|
CVE-2014-4682
|
2014-07-25 23:27 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257812
|
- |
|
micropact
|
icomplaints
|
Cross-site scripting (XSS) vulnerability in AddStdLetter.jsp in MicroPact iComplaints before 8.0.2.1.8.8014 allows remote authenticated users to inject arbitrary web script or HTML via the descriptio…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2971
|
2014-07-25 23:00 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257813
|
- |
|
honeywell
|
falcon_xlweb_linux_controller falcon_xlweb_xlwebexe
|
Honeywell FALCON XLWeb Linux controller devices 2.04.01 and earlier and FALCON XLWeb XLWebExe controller devices 2.02.11 and earlier allow remote attackers to bypass authentication and obtain adminis…
|
NVD-CWE-Other
|
CVE-2014-2717
|
2014-07-25 22:52 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257814
|
- |
|
honeywell
|
falcon_xlweb_linux_controller falcon_xlweb_xlwebexe
|
<a href="http://cwe.mitre.org/data/definitions/552.html" target="_blank">CWE-552: CWE-552: Files or Directories Accessible to External Parties</a>
|
NVD-CWE-Other
|
CVE-2014-2717
|
2014-07-25 22:52 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257815
|
- |
|
huawei
|
e355_web_ui e355_firmware e355
|
Cross-site scripting (XSS) vulnerability in the web interface on the Huawei E355 CH1E355SM modem with software 21.157.37.01.910 and Web UI 11.001.08.00.03 allows remote attackers to inject arbitrary …
|
CWE-79
Cross-site Scripting
|
CVE-2014-2968
|
2014-07-25 03:49 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257816
|
- |
|
huawei
|
e355_web_ui e355_firmware e355
|
Per: http://www.kb.cert.org/vuls/id/688812
"The following device configuration was reported to be vulnerable. Other versions may be affected:
Hardware version: CH1E355SM
Software version: 21.157.37…
|
CWE-79
Cross-site Scripting
|
CVE-2014-2968
|
2014-07-25 03:49 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257817
|
- |
|
omron
|
ns_series_system_program_firmware ns10_hmi_terminal ns12_hmi_terminal ns15_hmi_terminal ns5_hmi_terminal ns8_hmi_terminal
|
Cross-site request forgery (CSRF) vulnerability in the web application on Omron NS5, NS8, NS10, NS12, and NS15 HMI terminals 8.1xx through 8.68x allows remote authenticated users to hijack the authen…
|
CWE-352
Origin Validation Error
|
CVE-2014-2369
|
2014-07-25 03:29 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257818
|
- |
|
attachmate
|
verastream_process_designer
|
Unrestricted file upload vulnerability in Attachmate Verastream Process Designer (VPD) before R6 SP1 Hotfix 1 allows remote attackers to execute arbitrary code by uploading and launching an executabl…
|
NVD-CWE-Other
|
CVE-2014-0607
|
2014-07-25 02:33 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257819
|
- |
|
attachmate
|
verastream_process_designer
|
<a href="http://cwe.mitre.org/data/definitions/434.html" target="_blank">CWE-434: Unrestricted Upload of File with Dangerous Type</a>
|
NVD-CWE-Other
|
CVE-2014-0607
|
2014-07-25 02:33 |
2014-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
257820
|
- |
|
yiiframework
|
yiiframework
|
The CDetailView widget in Yii PHP Framework 1.1.14 allows remote attackers to execute arbitrary PHP scripts via vectors related to the value property.
|
CWE-94
Code Injection
|
CVE-2014-4672
|
2014-07-24 14:01 |
2014-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|