CVE-2014-10000 to CVE-2014-10999
28 CVEs with public proof-of-concept exploits.
- CVE-2014-100012 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Appointment Scheduler 2.0 allow remote attackers to hijack the…
- CVE-2014-100081 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in Stark CRM 1.0 allow remote attackers to hijack the authentication of…
- CVE-2014-100091 PoCMultiple cross-site scripting (XSS) vulnerabilities in Stark CRM 1.0 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2014-100102 PoCsDirectory traversal vulnerability in PHPJabbers Appointment Scheduler 2.0 allows remote attackers to read arbitrary files via a .. (dot…
- CVE-2014-100111 PoCStack-based buffer overflow in UltraCamLib in the UltraCam ActiveX Control (UltraCamX.ocx) for the TRENDnet SecurView camera TV-IP422WN…
- CVE-2014-100132 PoCsSQL injection vulnerability in the Another WordPress Classifieds Plugin plugin for WordPress allows remote attackers to execute arbitrary…
- CVE-2014-100141 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in PHPJabbers Event Booking Calendar 2.0 allow remote attackers to hijack the…
- CVE-2014-100151 PoCSQL injection vulnerability in load-calendar.php in PHPJabbers Event Booking Calendar 2.0 allows remote attackers to execute arbitrary SQL…
- CVE-2014-100182 PoCsCross-site scripting (XSS) vulnerability in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem allows remote…
- CVE-2014-100192 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in webconfig/wlan/country.html/country in the Teracom T2-B-Gawv1.4U10Y-BI modem…
- CVE-2014-100202 PoCsSQL injection vulnerability in login.php in Simple e-document 1.31 allows remote attackers to execute arbitrary SQL commands via the…
- CVE-2014-100214 PoCsUnrestricted file upload vulnerability in UploadHandler.php in the WP Symposium plugin 14.11 for WordPress allows remote attackers to…
- CVE-2014-100232 PoCsMultiple SQL injection vulnerabilities in TopicsViewer 3.0 Beta 1 allow remote attackers to execute arbitrary SQL commands via the id…
- CVE-2014-100291 PoCSQL injection vulnerability in profile.php in FluxBB before 1.4.13 and 1.5.x before 1.5.7 allows remote attackers to execute arbitrary SQL…
- CVE-2014-100312 PoCsBuffer overflow in the IMAPd service in Qualcomm Eudora WorldMail 9.0.333.0 allows remote attackers to execute arbitrary code via a long…
- CVE-2014-100322 PoCsSQL injection vulnerability in news_popup.php in Taboada MacroNews 1.0 allows remote authenticated users to execute arbitrary SQL commands…
- CVE-2014-100332 PoCsSQL injection vulnerability in the update_zone function in catalog/admin/geo_zones.php in osCommerce Online Merchant 2.3.3.4 and earlier…
- CVE-2014-100342 PoCsMultiple SQL injection vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to execute arbitrary SQL…
- CVE-2014-100352 PoCsMultiple cross-site scripting (XSS) vulnerabilities in the admin area in couponPHP before 1.2.0 allow remote administrators to inject…
- CVE-2014-100373 PoCsDirectory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a .. (dot dot) in the…
- CVE-2014-100382 PoCsSQL injection vulnerability in agenda/indexdate.php in DomPHP 0.83 and earlier allows remote attackers to execute arbitrary SQL commands…
- CVE-2014-100651 PoCCertain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing…
- CVE-2014-100741 PoCUmbraco before 7.2.0 has a remote PHP code execution vulnerability because Umbraco.Web.UI/config/umbracoSettings.Release.config does not…
- CVE-2014-100761 PoCThe wp-db-backup plugin 2.2.4 for WordPress relies on a five-character string for access control, which makes it easier for remote…
- CVE-2014-100781 PoCVembu StoreGrid 4.4.x has XSS in interface/registercustomer/onlineregsuccess.php, interface/registerreseller/onlineregfailure.php,…
- CVE-2014-100791 PoCIn Vembu StoreGrid 4.4.x, the front page of the server web interface leaks the private IP address in the "ipaddress" hidden form value of…
- CVE-2014-103961 PoCThe epic theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to includes/download.php.
- CVE-2014-103971 PoCThe Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts/download.php.