8.8
    High

    CVE-2014-6278

    Last Modified: 15 Nov 2017

    GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary commands via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271, CVE-2014-7169, and CVE-2014-6277.

    Source:lastc0de
    Published:29 Sept 2014
    10
    Critical

    CVE-2014-6277

    Last Modified: 14 Jul 2017

    GNU Bash through 4.3 bash43-026 does not properly parse function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code or cause a denial of service (uninitialized memory access, and untrusted-pointer read and write operations) via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-6271 and CVE-2014-7169.

    Source:Michal Zalewski
    Published:27 Sept 2014
    9.8
    Critical

    CVE-2014-6271

    Last Modified: 22 Jan 2018

    GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the Apache HTTP Server, scripts executed by unspecified DHCP clients, and other situations in which setting the environment occurs across a privilege boundary from Bash execution, aka "ShellShock." NOTE: the original fix for this issue was incorrect; CVE-2014-7169 has been assigned to cover the vulnerability that is still present after the incorrect fix.

    Source:Metasploit
    Published:24 Sept 2014
    6.5
    Medium

    CVE-2014-6242

    Last Modified: 25 Sept 2014

    Multiple SQL injection vulnerabilities in the All In One WP Security & Firewall plugin before 3.8.3 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) orderby or (2) order parameter in the aiowpsec page to wp-admin/admin.php. NOTE: this can be leveraged using CSRF to allow remote attackers to execute arbitrary SQL commands.

    Source:High-Tech Bridge SA
    Published:2 Oct 2014
    7.5
    High

    CVE-2014-6235

    Last Modified: 13 Oct 2017

    Unspecified vulnerability in the ke DomPDF extension before 0.0.5 for TYPO3 allows remote attackers to execute arbitrary code via unknown vectors.

    Source:RedTeam Pentesting
    Published:11 Sept 2014
    4.3
    Medium

    CVE-2014-6137

    Last Modified: 11 Feb 2015

    Cross-site scripting (XSS) vulnerability in the Relay Diagnostic page in IBM Tivoli Endpoint Manager 9.1 before 9.1.1229 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:RedTeam Pentesting
    Published:16 Feb 2015
    4.3
    Medium

    CVE-2014-6070

    Last Modified: 8 Sept 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Adiscon LogAnalyzer before 3.6.6 allow remote attackers to inject arbitrary web script or HTML via the hostname in (1) index.php or (2) detail.php.

    Source:Dolev Farhi
    Published:11 Sept 2014
    5.3
    Medium

    CVE-2014-6050

    Last Modified: 9 Sept 2014

    phpMyFAQ before 2.8.13 allows remote attackers to bypass the CAPTCHA protection mechanism by replaying the request.

    Source:smash
    Published:28 Aug 2018
    2.7
    Low

    CVE-2014-6049

    Last Modified: 9 Sept 2014

    phpMyFAQ before 2.8.13 allows remote authenticated users with admin privileges to bypass authorization via a crafted instance ID parameter.

    Source:smash
    Published:28 Aug 2018
    5.3
    Medium

    CVE-2014-6048

    Last Modified: 9 Sept 2014

    phpMyFAQ before 2.8.13 allows remote attackers to read arbitrary attachments via a direct request.

    Source:smash
    Published:28 Aug 2018
    5.3
    Medium

    CVE-2014-6047

    Last Modified: 9 Sept 2014

    phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to read arbitrary attachments by leveraging incorrect "download an attachment" permission checks.

    Source:smash
    Published:28 Aug 2018
    8.8
    High

    CVE-2014-6046

    Last Modified: 9 Sept 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in phpMyFAQ before 2.8.13 allow remote attackers to hijack the authentication of unspecified users for requests that (1) delete active users by leveraging improper validation of CSRF tokens or that (2) delete open questions, (3) activate users, (4) publish FAQs, (5) add or delete Glossary, (6) add or delete FAQ news, or (7) add or delete comments or add votes by leveraging lack of a CSRF token.

    Source:smash
    Published:28 Aug 2018
    7.2
    High

    CVE-2014-6045

    Last Modified: 9 Sept 2014

    SQL injection vulnerability in phpMyFAQ before 2.8.13 allows remote authenticated users with certain permissions to execute arbitrary SQL commands via vectors involving the restore function.

    Source:smash
    Published:28 Aug 2018
    6.5
    Medium

    CVE-2014-6043

    Last Modified: 25 Jan 2018

    ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 does not properly restrict access to the database browser, which allows remote authenticated users to obtain access to the database via a direct request to event/runQuery.do. Fixed in Build 10000.

    Source:Hans-Martin Muench
    Published:11 Sept 2014
    7.5
    High

    CVE-2014-6039

    Last Modified: 25 Jan 2018

    ManageEngine EventLog Analyzer version 7 through 9.9 build 9002 has a Credentials Disclosure Vulnerability. Fixed version 10 Build 10000.

    Source:Pedro Ribeiro
    Published:13 Jan 2020
    7.5
    High

    CVE-2014-6038

    Last Modified: 25 Jan 2018

    Zoho ManageEngine EventLog Analyzer versions 7 through 9.9 build 9002 have a database Information Disclosure Vulnerability. Fixed in EventLog Analyzer 10.0 Build 10000.

    Source:Pedro Ribeiro
    Published:13 Jan 2020
    7.5
    High

    CVE-2014-6037

    Last Modified: 25 Jan 2018

    Directory traversal vulnerability in the agentUpload servlet in ZOHO ManageEngine EventLog Analyzer 9.0 build 9002 and 8.2 build 8020 allows remote attackers to execute arbitrary code by uploading a ZIP file which contains an executable file with .. (dot dot) sequences in its name, then accessing the executable via a direct request to the file under the web root. Fixed in Build 11072.

    Source:Hans-Martin Muench
    Published:26 Oct 2014
    6.4
    Medium

    CVE-2014-6036

    Last Modified: 25 Jan 2018

    Directory traversal vulnerability in the multipartRequest servlet in ZOHO ManageEngine OpManager 11.3 and earlier, Social IT Plus 11.0, and IT360 10.3, 10.4, and earlier allows remote attackers or remote authenticated users to delete arbitrary files via a .. (dot dot) in the fileName parameter.

    Source:Pedro Ribeiro
    Published:4 Dec 2014
    7.5
    High

    CVE-2014-6035

    Last Modified: 25 Jan 2018

    Directory traversal vulnerability in the FileCollector servlet in ZOHO ManageEngine OpManager 11.4, 11.3, and earlier allows remote attackers to write and execute arbitrary files via a .. (dot dot) in the FILENAME parameter.

    Source:Pedro Ribeiro
    Published:4 Dec 2014
    5
    Medium

    CVE-2014-6034

    Last Modified: 2 Oct 2014

    Directory traversal vulnerability in the com.me.opmanager.extranet.remote.communication.fw.fe.FileCollector servlet in ZOHO ManageEngine OpManager 8.8 through 11.3, Social IT Plus 11.0, and IT360 10.4 and earlier allows remote attackers or remote authenticated users to write to and execute arbitrary WAR files via a .. (dot dot) in the regionID parameter.

    Source:Pedro Ribeiro
    Published:4 Dec 2014
    6.5
    Medium

    CVE-2014-6030

    Last Modified: 20 Sept 2014

    Multiple SQL injection vulnerabilities in ClassApps SelectSurvey.NET before 4.125.002 allow (1) remote attackers to execute arbitrary SQL commands via the SurveyID parameter to survey/ReviewReadOnlySurvey.aspx or (2) remote authenticated users to execute arbitrary SQL commands via the SurveyID parameter to survey/UploadImagePopupToDb.aspx.

    Source:BillV-Lists
    Published:6 Nov 2014
    6.5
    Medium

    CVE-2014-5521

    Last Modified: 28 Aug 2014

    plugins/useradmin/fingeruser.php in XRMS CRM, possibly 1.99.2, allows remote authenticated users to execute arbitrary code via shell metacharacters in the username parameter.

    Source:Benjamin Harris
    Published:2 Sept 2014
    7.5
    High

    CVE-2014-5520

    Last Modified: 28 Aug 2014

    SQL injection vulnerability in XRMS CRM, possibly 1.99.2, allows remote attackers to execute arbitrary SQL commands via the user_id parameter to plugins/webform/new-form.php, which is not properly handled by plugins/useradmin/fingeruser.php.

    Source:Benjamin Harris
    Published:26 Oct 2014
    7.5
    High

    CVE-2014-5519

    Last Modified: 28 Aug 2014

    The Ploticus module in PhpWiki 1.5.0 allows remote attackers to execute arbitrary code via shell metacharacters in a device option in the edit[content] parameter to index.php/HeIp. NOTE: some of these details are obtained from third party information.

    Source:Benjamin Harris
    Published:11 Sept 2014
    7.2
    High

    CVE-2014-5507

    Last Modified: 22 Oct 2014

    iBackup 10.0.0.32 and earlier uses weak permissions (Everyone: Full Control) for ib_service.exe, which allows local users to gain privileges via a Trojan horse file.

    Source:Glafkos Charalambous
    Published:3 Nov 2014
    9.8
    Critical

    CVE-2014-5470

    Last Modified: 16 Dec 2014

    Actual Analyzer through 2014-08-29 allows code execution via shell metacharacters because untrusted input is used for part of the input data passed to an eval operation.

    Source:Metasploit
    Published:21 Jun 2024
    Unknown

    CVE-2014-5469

    https://www.exploit-db.com/exploits/34513

    8.8
    High

    CVE-2014-5468

    Last Modified: 24 Oct 2016

    A File Inclusion vulnerability exists in Railo 4.2.1 and earlier via a specially-crafted URL request to the thumbnail.cfm to specify a malicious PNG file, which could let a remote malicious user obtain sensitive information or execute arbitrary code.

    Source:Metasploit
    Published:7 Feb 2020
    5
    Medium

    CVE-2014-5465

    Last Modified: 28 Aug 2014

    Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:Mehdi Karout & Christian Galeone
    Published:3 Sept 2014
    4.3
    Medium

    CVE-2014-5464

    Last Modified: 26 Aug 2014

    Cross-site scripting (XSS) vulnerability in the nDPI traffic classification library in ntopng (aka ntop) before 1.2.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Host header.

    Source:Steffen Bauch
    Published:8 Sept 2014
    6.5
    Medium

    CVE-2014-5462

    Last Modified: 10 Oct 2016

    Multiple SQL injection vulnerabilities in OpenEMR 4.1.2 (Patch 7) and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) layout_id parameter to interface/super/edit_layout.php; (2) form_patient_id, (3) form_drug_name, or (4) form_lot_number parameter to interface/reports/prescriptions_report.php; (5) payment_id parameter to interface/billing/edit_payment.php; (6) id parameter to interface/forms_admin/forms_admin.php; (7) form_pid or (8) form_encounter parameter to interface/billing/sl_eob_search.php; (9) sortby parameter to interface/logview/logview.php; form_facility parameter to (10) procedure_stats.php, (11) pending_followup.php, or (12) pending_orders.php in interface/orders/; (13) patient, (14) encounterid, (15) formid, or (16) issue parameter to interface/patient_file/deleter.php; (17) search_term parameter to interface/patient_file/encounter/coding_popup.php; (18) text parameter to interface/patient_file/encounter/search_code.php; (19) form_addr1, (20) form_addr2, (21) form_attn, (22) form_country, (23) form_freeb_type, (24) form_partner, (25) form_name, (26) form_zip, (27) form_state, (28) form_city, or (29) form_cms_id parameter to interface/practice/ins_search.php; (30) form_pid parameter to interface/patient_file/problem_encounter.php; (31) patient, (32) form_provider, (33) form_apptstatus, or (34) form_facility parameter to interface/reports/appointments_report.php; (35) db_id parameter to interface/patient_file/summary/demographics_save.php; (36) p parameter to interface/fax/fax_dispatch_newpid.php; or (37) patient_id parameter to interface/patient_file/reminder/patient_reminders.php.

    Source:Portcullis
    Published:8 Dec 2014
    6.5
    Medium

    CVE-2014-5460

    Last Modified: 7 Oct 2014

    Unrestricted file upload vulnerability in the Tribulant Slideshow Gallery plugin before 1.4.7 for WordPress allows remote authenticated users to execute arbitrary code by uploading a PHP file, then accessing it via a direct request to the file in wp-content/uploads/slideshow-gallery/.

    Source:Claudio Viviani
    Published:11 Sept 2014
    5.3
    Medium

    CVE-2014-5455

    Last Modified: 14 Jul 2014

    Unquoted Windows search path vulnerability in the ptservice service prior to PrivateTunnel version 3.0 (Windows) and OpenVPN Connect version 3.1 (Windows) allows local users to gain privileges via a crafted program.exe file in the %SYSTEMDRIVE% folder.

    Source:LiquidWorm
    Published:25 Aug 2014
    7.2
    High

    CVE-2014-5453

    Last Modified: 9 Jul 2014

    Ubisoft Uplay PC before 4.6.1.3217 use weak permissions (Everyone: Full Control) for the program installation directory (%PROGRAMFILES%\Ubisoft Game Launcher), which allows local users to gain privileges via a Trojan horse file.

    Source:LiquidWorm
    Published:25 Aug 2014
    5
    Medium

    CVE-2014-5446

    Last Modified: 25 Jan 2018

    Directory traversal vulnerability in the DisplayChartPDF servlet in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allows remote attackers and remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter.

    Source:Pedro Ribeiro
    Published:4 Dec 2014
    5
    Medium

    CVE-2014-5445

    Last Modified: 25 Jan 2018

    Multiple absolute path traversal vulnerabilities in ZOHO ManageEngine Netflow Analyzer 8.6 through 10.2 and IT360 10.3 allow remote attackers or remote authenticated users to read arbitrary files via a full pathname in the schFilePath parameter to the (1) CSVServlet or (2) CReportPDFServlet servlet.

    Source:Pedro Ribeiro
    Published:4 Dec 2014
    6.8
    Medium

    CVE-2014-5395

    Last Modified: 7 Jan 2019

    Multiple cross-site request forgery (CSRF) vulnerabilities in Huawei HiLink E3276 and E3236 TCPU before V200R002B470D13SP00C00 and WebUI before V100R007B100D03SP01C03, E5180s-22 before 21.270.21.00.00, and E586Bs-2 before 21.322.10.00.889 allow remote attackers to hijack the authentication of users for requests that (1) modify configurations, (2) send SMS messages, or have other unspecified impact via unknown vectors.

    Source:Nathu Nandwani
    Published:21 Nov 2014
    6.5
    Medium

    CVE-2014-5383

    Last Modified: 16 Dec 2016

    SQL injection vulnerability in AlienVault OSSIM before 4.7.0 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

    Source:Chris Hebert
    Published:21 Aug 2014
    9.8
    Critical

    CVE-2014-5381

    Last Modified: 22 Jan 2016

    Grand MA 300 allows a brute-force attack on the PIN.

    Source:Eric Sesterhenn
    Published:13 Jan 2020
    7.5
    High

    CVE-2014-5380

    Last Modified: 11 Jan 2018

    Grand MA 300 allows retrieval of the access PIN from sniffed data.

    Source:Eric Sesterhenn
    Published:13 Jan 2020
    5
    Medium

    CVE-2014-5377

    Last Modified: 25 Jan 2018

    ReadUsersFromMasterServlet in ManageEngine DeviceExpert before 5.9 build 5981 allows remote attackers to obtain user account credentials via a direct request.

    Source:Pedro Ribeiro
    Published:4 Sept 2014
    7.5
    High

    CVE-2014-5370

    Last Modified: 10 Oct 2016

    Directory traversal vulnerability in the CFChart servlet (com.naryx.tagfusion.cfm.cfchartServlet) in New Atlanta BlueDragon before 7.1.1.18527 allows remote attackers to read or possibly delete arbitrary files via a .. (dot dot) in the QUERY_STRING to cfchart.cfchart.

    Source:Portcullis
    Published:21 Apr 2015
    5
    Medium

    CVE-2014-5368

    Last Modified: 22 Jan 2016

    Directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Source Control (wp-source-control) plugin 3.0.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter.

    Source:Henri Salo
    Published:22 Aug 2014
    5
    Medium

    CVE-2014-5350

    Last Modified: 16 Jul 2014

    Multiple directory traversal vulnerabilities in Bitdefender GravityZone before 5.1.11.432 allow remote attackers to read arbitrary files via a (1) .. (dot dot) in the id parameter to webservice/CORE/downloadFullKitEpc/a/1 in the Web Console or (2) %2E%2E (encoded dot dot) in the default URI to port 7074 on the Update Server.

    Source:SEC Consult
    Published:19 Aug 2014
    5
    Medium

    CVE-2014-5349

    Last Modified: 2 Jul 2014

    Stack-based buffer overflow in Baidu Spark Browser 26.5.9999.3511 allows remote attackers to cause a denial of service (application crash) via nested calls to the window.print JavaScript function.

    Source:LiquidWorm
    Published:19 Aug 2014
    6.8
    Medium

    CVE-2014-5347

    Last Modified: 14 Aug 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin before 2.76 for WordPress allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks via the (1) disqus_replace, (2) disqus_public_key, or (3) disqus_secret_key parameter to wp-admin/edit-comments.php in manage.php or that (4) reset or (5) delete plugin options via the reset parameter to wp-admin/edit-comments.php.

    Source:Nik Cubrilovic
    Published:19 Aug 2014
    6.8
    Medium

    CVE-2014-5346

    Last Modified: 14 Aug 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in the Disqus Comment System plugin 2.77 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) activate or (2) deactivate the plugin via the active parameter to wp-admin/edit-comments.php, (3) import comments via an import_comments action, or (4) export comments via an export_comments action to wp-admin/index.php.

    Source:Nik Cubrilovic
    Published:19 Aug 2014
    4.3
    Medium

    CVE-2014-5345

    Last Modified: 14 Aug 2014

    Cross-site scripting (XSS) vulnerability in upgrade.php in the Disqus Comment System plugin before 2.76 for WordPress allows remote attackers to inject arbitrary web script or HTML via the step parameter.

    Source:Nik Cubrilovic
    Published:19 Aug 2014
    6.8
    Medium

    CVE-2014-5335

    Last Modified: 25 Aug 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in innovaphone PBX 10.00 sr11 and earlier allow remote attackers to hijack the authentication of administrators for requests that modify configurations or user accounts, as demonstrated by (1) changing the administrator password via a crafted request to CMD0/mod_cmd.xml or (2) adding a new SIP user via a crafted request to PBX0/ADMIN/mod_cmd_login.xml.

    Source:Rainer Giedat
    Published:25 Aug 2014
    7.5
    High

    CVE-2014-5329

    Last Modified: 9 Dec 2011

    GIGAPOD file servers (Appliance model and Software model) provide two web interfaces, 80/tcp and 443/tcp for user operation, and 8001/tcp for administrative operation. 8001/tcp is served by a version of Apache HTTP server containing a flaw in handling HTTP requests (CVE-2011-3192), which may lead to a denial-of-service (DoS) condition.

    Source:Ramon de C Valle
    Published:8 Sept 2023