258201
|
- |
|
gitlist
|
gitlist
|
Repository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell metacharacters in a branch name, as demonstrated by a "git checkou…
|
NVD-CWE-Other
|
CVE-2014-5023
|
2014-07-23 00:20 |
2014-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258202
|
- |
|
gitlist
|
gitlist
|
<a href="http://cwe.mitre.org/data/definitions/77.html" target="_blank">CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection'</a>
|
NVD-CWE-Other
|
CVE-2014-5023
|
2014-07-23 00:20 |
2014-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258203
|
- |
|
gitlist
|
gitlist
|
Gitlist allows remote attackers to execute arbitrary commands via shell metacharacters in a file name to Source/.
|
NVD-CWE-Other
|
CVE-2013-7392
|
2014-07-23 00:14 |
2014-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258204
|
- |
|
gitlist
|
gitlist
|
<a href="http://cwe.mitre.org/data/definitions/77.html" target="_blank">CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection'</a>
|
NVD-CWE-Other
|
CVE-2013-7392
|
2014-07-23 00:14 |
2014-07-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258205
|
- |
|
limesurvey
|
limesurvey
|
SQL injection vulnerability in CPDB in application/controllers/admin/participantsaction.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to execute arbitrary SQL commands via the sidx par…
|
CWE-89
SQL Injection
|
CVE-2014-5017
|
2014-07-22 23:01 |
2014-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258206
|
- |
|
limesurvey
|
limesurvey
|
Incomplete blacklist vulnerability in the autoEscape function in common_helper.php in LimeSurvey 2.05+ Build 140618 allows remote attackers to conduct cross-site scripting (XSS) attacks via the GBK c…
|
NVD-CWE-Other
|
CVE-2014-5018
|
2014-07-22 23:01 |
2014-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258207
|
- |
|
limesurvey
|
limesurvey
|
<a href="http://cwe.mitre.org/data/definitions/184.html" target="_blank">CWE-184: Incomplete Blacklist</a>
|
NVD-CWE-Other
|
CVE-2014-5018
|
2014-07-22 23:01 |
2014-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258208
|
- |
|
limesurvey
|
limesurvey
|
Multiple cross-site scripting (XSS) vulnerabilities in LimeSurvey 2.05+ Build 140618 allow remote attackers to inject arbitrary web script or HTML via (1) the pid attribute to the getAttribute_json f…
|
CWE-79
Cross-site Scripting
|
CVE-2014-5016
|
2014-07-22 22:58 |
2014-07-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258209
|
- |
|
redhat
|
enterprise_mrg
|
Cumin (aka MRG Management Console), as used in Red Hat Enterprise MRG 2.5, uses the DES-based crypt function to hash passwords, which makes it easier for attackers to obtain sensitive information via…
|
CWE-310
Cryptographic Issues
|
CVE-2013-6445
|
2014-07-19 03:50 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
258210
|
- |
|
super_project
|
super
|
super.c in Super 3.30.0 does not check the return value of the setuid function when the -F flag is set, which allows local users to gain privileges via unspecified vectors, aka an RLIMIT_NPROC attack.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2014-0470
|
2014-07-19 03:40 |
2014-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|