CVE-2014-5000 to CVE-2014-5999
99 CVEs with public proof-of-concept exploits.
- CVE-2014-50055 PoCsDirectory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute…
- CVE-2014-50064 PoCsDirectory traversal vulnerability in ZOHO ManageEngine Desktop Central (DC) before 9 build 90055 allows remote attackers to execute…
- CVE-2014-50074 PoCsDirectory traversal vulnerability in the agentLogUploader servlet in ZOHO ManageEngine Desktop Central (DC) and Desktop Central Managed…
- CVE-2014-50231 PoCRepository.php in Gitter, as used in Gitlist, allows remote attackers with commit privileges to execute arbitrary commands via shell…
- CVE-2014-50242 PoCsCross-site scripting (XSS) vulnerability in sgms/panelManager in Dell SonicWALL GMS, Analyzer, and UMA before 7.2 SP1 allows remote…
- CVE-2014-50342 PoCsCross-site request forgery (CSRF) vulnerability in the Brute Force Login Protection module 1.3 for WordPress allows remote attackers to…
- CVE-2014-50733 PoCsvmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell…
- CVE-2014-50741 PoCSiemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device restart and STOP…
- CVE-2014-50812 PoCssphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass
- CVE-2014-50823 PoCsMultiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote…
- CVE-2014-50832 PoCsA Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a…
- CVE-2014-50842 PoCsA Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious…
- CVE-2014-50852 PoCsA Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a…
- CVE-2014-50862 PoCsA Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php,…
- CVE-2014-50872 PoCsA vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote…
- CVE-2014-50881 PoCCross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to…
- CVE-2014-50891 PoCSQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL…
- CVE-2014-50901 PoCadmin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in…
- CVE-2014-50913 PoCsA vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a…
- CVE-2014-50922 PoCsStatus2k allows Remote Command Execution in admin/options/editpl.php.
- CVE-2014-50932 PoCsStatus2k does not remove the install directory allowing credential reset.
- CVE-2014-50941 PoCStatus2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls…
- CVE-2014-50971 PoCMultiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execute arbitrary SQL…
- CVE-2014-51002 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the authentication of…
- CVE-2014-51011 PoCMultiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2014-51044 PoCsMultiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) a_country…
- CVE-2014-51092 PoCsSQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute…
- CVE-2014-51101 PoCCross-site scripting (XSS) vulnerability in user/help/html/index.php in Fonality trixbox allows remote attackers to inject arbitrary web…
- CVE-2014-51115 PoCsMultiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the…
- CVE-2014-51121 PoCmaint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the…
- CVE-2014-51152 PoCsAbsolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname in the phpfile…
- CVE-2014-51162 PoCsThe cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a…
- CVE-2014-51192 PoCsOff-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to…
- CVE-2014-51392 PoCsThe ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service…
- CVE-2014-51403 PoCsThe bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon)…
- CVE-2014-51441 PoCCross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary web script or…
- CVE-2014-51801 PoCSQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 for WordPress allows…
- CVE-2014-51811 PoCDirectory traversal vulnerability in lastfm-proxy.php in the Last.fm Rotation (lastfm-rotation) plugin 1.0 for WordPress allows remote…
- CVE-2014-51871 PoCDirectory traversal vulnerability in the Tom M8te (tom-m8te) plugin 1.5.3 for WordPress allows remote attackers to read arbitrary files…
- CVE-2014-51891 PoCSQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin for WordPress allows remote attackers to execute…
- CVE-2014-51922 PoCsSQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter…
- CVE-2014-51932 PoCsCross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or…
- CVE-2014-51942 PoCsStatic code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code…
- CVE-2014-52001 PoCSQL injection vulnerability in game_play.php in the FB Gorilla plugin for WordPress allows remote attackers to execute arbitrary SQL…
- CVE-2014-52011 PoCSQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary SQL commands via…
- CVE-2014-52031 PoCwp-includes/class-wp-customize-widgets.php in the widget implementation in WordPress 3.9.x before 3.9.2 might allow remote attackers to…
- CVE-2014-52041 PoCwp-includes/pluggable.php in WordPress before 3.9.2 rejects invalid CSRF nonces with a different timing depending on which characters in…
- CVE-2014-52051 PoCwp-includes/pluggable.php in WordPress before 3.9.2 does not use delimiters during concatenation of action values and uid values in CSRF…
- CVE-2014-52073 PoCsfs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing…
- CVE-2014-52081 PoCBKBCopyD.exe in the Batch Management Packages in Yokogawa CENTUM CS 3000 through R3.09.50 and CENTUM VP through R4.03.00 and R5.x through…
- CVE-2014-52101 PoCThe av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1)…
- CVE-2014-52161 PoCMultiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allow remote attackers to inject…
- CVE-2014-52401 PoCCross-site scripting (XSS) vulnerability in wp-includes/pluggable.php in WordPress before 3.9.2, when Multisite is enabled, allows remote…
- CVE-2014-52431 PoCMediaWiki before 1.19.18, 1.20.x through 1.22.x before 1.22.9, and 1.23.x before 1.23.2 does not enforce an IFRAME protection mechanism…
- CVE-2014-52462 PoCsThe Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain…
- CVE-2014-52582 PoCsDirectory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read…
- CVE-2014-52651 PoCThe Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, permits entity…
- CVE-2014-52662 PoCsThe Incutio XML-RPC (IXR) Library, as used in WordPress before 3.9.2 and Drupal 6.x before 6.33 and 7.x before 7.31, does not limit the…
- CVE-2014-52752 PoCsMultiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users…
- CVE-2014-52762 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to inject…
- CVE-2014-52844 PoCshost-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local…
- CVE-2014-52872 PoCsA Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User…
- CVE-2014-52882 PoCsA CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.
- CVE-2014-52892 PoCsBuffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request.
- CVE-2014-53002 PoCsAdaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary…
- CVE-2014-53016 PoCsDirectory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8…
- CVE-2014-53022 PoCsDirectory traversal vulnerability in ServiceDesk Plus and Plus MSP v5 through v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to…
- CVE-2014-53082 PoCsMultiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1)…
- CVE-2014-53292 PoCsGIGAPOD file servers (Appliance model and Software model) provide two web interfaces, 80/tcp and 443/tcp for user operation, and 8001/tcp…
- CVE-2014-53351 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attackers to hijack the…
- CVE-2014-53371 PoCThe WordPress Mobile Pack plugin before 2.0.2 for WordPress does not properly restrict access to password protected posts, which allows…
- CVE-2014-53451 PoCCross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote…
- CVE-2014-53461 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin 2.77 for WordPress allow remote attackers…
- CVE-2014-53472 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote…
- CVE-2014-53492 PoCsStack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (application crash)…
- CVE-2014-53501 PoCMultiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files…
- CVE-2014-53621 PoCThe admin interface in Landesk Management Suite 9.6 and earlier allows remote attackers to conduct remote file inclusion attacks involving…
- CVE-2014-53682 PoCsDirectory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Source Control…
- CVE-2014-53702 PoCsDirectory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before…
- CVE-2014-53774 PoCsReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials…
- CVE-2014-53803 PoCsGrand MA 300 allows retrieval of the access PIN from sniffed data.
- CVE-2014-53813 PoCsGrand MA 300 allows a brute-force attack on the PIN.
- CVE-2014-53832 PoCsSQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via…
- CVE-2014-53951 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI…
- CVE-2014-54391 PoCMultiple Stack-based Buffer Overflow vulnerabilities exists in Sniffit prior to 0.3.7 via a crafted configuration file that will bypass…
- CVE-2014-54455 PoCsMultiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote…
- CVE-2014-54462 PoCsDirectory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3…
- CVE-2014-54532 PoCsUbisoft Uplay PC before 4.6.1.3217 use weak permissions (Everyone: Full Control) for the program installation directory…
- CVE-2014-54552 PoCsUnquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect…
- CVE-2014-54607 PoCsUnrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated…
- CVE-2014-54621 PoCMultiple SQL injection vulnerabilities in OpenEMR 4.1.2 (Patch 7) and earlier allow remote authenticated users to execute arbitrary SQL…
- CVE-2014-54642 PoCsCross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote…
- CVE-2014-54652 PoCsDirectory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote…
- CVE-2014-54684 PoCsA File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a…
- CVE-2014-54702 PoCsActual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input…
- CVE-2014-55072 PoCsiBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local users to gain…
- CVE-2014-55193 PoCsThe Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the…
- CVE-2014-55202 PoCsSQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id…
- CVE-2014-55212 PoCsplugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell…