CVE-2014-6000 to CVE-2014-6999
48 CVEs with public proof-of-concept exploits.
- CVE-2014-60271 PoCMultiple cross-site scripting (XSS) vulnerabilities in TorrentFlux 2.4 allow (1) remote attackers to inject arbitrary web script or HTML…
- CVE-2014-60301 PoCMultiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to execute arbitrary SQL…
- CVE-2014-60344 PoCsDirectory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine…
- CVE-2014-60352 PoCsDirectory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier allows remote…
- CVE-2014-60362 PoCsDirectory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0,…
- CVE-2014-60374 PoCsDirectory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020…
- CVE-2014-60382 PoCsZoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in…
- CVE-2014-60393 PoCsManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.
- CVE-2014-60411 PoCThe Android WebView in Android before 4.4 allows remote attackers to bypass the Same Origin Policy via a crafted attribute containing a…
- CVE-2014-60432 PoCsZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which…
- CVE-2014-60451 PoCSQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL…
- CVE-2014-60461 PoCMultiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication…
- CVE-2014-60471 PoCphpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect…
- CVE-2014-60481 PoCphpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.
- CVE-2014-60491 PoCphpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter.
- CVE-2014-60501 PoCphpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.
- CVE-2014-60591 PoCWordPress Advanced Access Manager Plugin before 2.8.2 has an Arbitrary File Overwrite Vulnerability
- CVE-2014-60702 PoCsMultiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary web…
- CVE-2014-61371 PoCCross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote…
- CVE-2014-62351 PoCUnspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allows remote attackers to execute arbitrary code via unknown…
- CVE-2014-62422 PoCsMultiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow remote…
- CVE-2014-6271107 PoCsKEVGNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote…
- CVE-2014-62773 PoCsGNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote…
- CVE-2014-62788 PoCsKEVGNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote…
- CVE-2014-628727 PoCsKEVThe findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote…
- CVE-2014-63082 PoCsDirectory traversal vulnerability in OSClass before 3.4.2 allows remote attackers to read arbitrary files via a .. (dot dot) in the file…
- CVE-2014-63122 PoCsCross-site request forgery (CSRF) vulnerability in the Login Widget With Shortcode (login-sidebar-widget) plugin before 3.2.1 for…
- CVE-2014-63212 PoCsSchannel in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows…
- CVE-2014-63245 PoCsKEVThe Kerberos Key Distribution Center (KDC) in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1,…
- CVE-2014-633220 PoCsKEVOleAut32.dll in OLE in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8,…
- CVE-2014-63527 PoCsKEVMicrosoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2,…
- CVE-2014-63631 PoCvbscript.dll in Microsoft VBScript 5.6 through 5.8, as used with Internet Explorer 6 through 11 and other products, allows remote…
- CVE-2014-63892 PoCsbackup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the d…
- CVE-2014-63951 PoCHeap-based buffer overflow in the dissector_postgresql function in dissectors/ec_postgresql.c in Ettercap before 0.8.1 allows remote…
- CVE-2014-64092 PoCsCross-site request forgery (CSRF) vulnerability in M/Monit 3.3.2 and earlier allows remote attackers to hijack the authentication of…
- CVE-2014-64121 PoCWordPress before 4.4 makes it easier for remote attackers to predict password-recovery tokens via a brute-force approach.
- CVE-2014-64132 PoCsA Cross-site Scripting (XSS) vulnerability exists in WatchGuard XTM 11.8.3 via the poll_name parameter in the firewall/policy script.
- CVE-2014-64201 PoCCross-site scripting (XSS) vulnerability in Livefyre LiveComments 3.0 allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2014-64352 PoCscgi-bin/AZ_Retrain.cgi in Aztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices does not check for authentication, which allows…
- CVE-2014-64362 PoCsAztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices improperly manage sessions, which allows remote attackers to bypass…
- CVE-2014-64372 PoCsAztech ADSL DSL5018EN (1T1R), DSL705E, and DSL705EU devices allow remote attackers to obtain sensitive device configuration information…
- CVE-2014-64463 PoCsThe Infusionsoft Gravity Forms plugin 1.5.3 through 1.5.10 for WordPress does not properly restrict access, which allows remote attackers…
- CVE-2014-65771 PoCUnspecified vulnerability in the XML Developer's Kit for C component in Oracle Database Server 11.2.0.3, 11.2.0.4, 12.1.0.1, and 12.1.0.2…
- CVE-2014-65932 PoCsUnspecified vulnerability in Oracle Java SE 5.0u75, 6u85, 7u72, and 8u25; Java SE Embedded 7u71 and 8u6; and JRockit 27.8.4 and 28.3.4…
- CVE-2014-66072 PoCsM/Monit 3.3.2 and earlier does not verify the original password before changing passwords, which allows remote attackers to change the…
- CVE-2014-66171 PoCSofting FG-100 PB PROFIBUS firmware version FG-x00-PB_V2.02.0.00 contains a hardcoded password for the root account, which allows remote…
- CVE-2014-66192 PoCsMultiple cross-site scripting (XSS) vulnerabilities in register-exec.php in Restaurant Script (PizzaInn_Project) 1.0.0 allow remote…
- CVE-2014-67211 PoCThe Pharmaguideline (aka com.pharmaguideline) application 1.2.0 for Android does not verify X.509 certificates from SSL servers, which…