9
    Critical

    CVE-2014-5308

    Last Modified: 10 Oct 2016

    Multiple SQL injection vulnerabilities in TestLink 1.9.11 allow remote authenticated users to execute arbitrary SQL commands via the (1) name parameter in a Search action to lib/project/projectView.php or (2) id parameter to lib/events/eventinfo.php.

    Source:Portcullis
    Published:8 Oct 2014
    8.8
    High

    CVE-2014-5301

    Last Modified: 20 Jan 2015

    Directory traversal vulnerability in ServiceDesk Plus MSP v5 to v9.0 v9030; AssetExplorer v4 to v6.1; SupportCenter v5 to v7.9; IT360 v8 to v10.4.

    Source:Metasploit
    Published:28 Aug 2017
    5
    Medium

    CVE-2014-5300

    Last Modified: 2 Oct 2014

    Adaptive Computing Moab before 7.2.9 and 8 before 8.0.0 allows remote attackers to bypass the signature check, impersonate arbitrary users, and execute commands via a message without a signature.

    Source:MWR InfoSecurity
    Published:8 Oct 2014
    9.8
    Critical

    CVE-2014-5289

    Last Modified: 18 Aug 2017

    Buffer overflow in Senkas Kolibri 2.0 allows remote attackers to execute arbitrary code via a long URI in a POST request.

    Source:tekwizz123
    Published:27 Dec 2019
    8.8
    High

    CVE-2014-5288

    Last Modified: 2 Apr 2015

    A CSRF Vulnerability exists in Kemp Load Master before 7.0-18a via unspecified vectors in administrative pages.

    Source:Roberto Suggi Liverani
    Published:7 Feb 2020
    8.8
    High

    CVE-2014-5287

    Last Modified: 2 Apr 2015

    A Bash script injection vulnerability exists in Kemp Load Master 7.1-16 and earlier due to a failure to sanitize input in the Web User Interface (WUI).

    Source:Roberto Suggi Liverani
    Published:8 Jan 2020
    7.2
    High

    CVE-2014-5284

    Last Modified: 18 Nov 2014

    host-deny.sh in OSSEC before 2.8.1 writes to temporary files with predictable filenames without verifying ownership, which allows local users to modify access restrictions in hosts.deny and gain root privileges by creating the temporary files before automatic IP blocking is performed.

    Source:skynet-13
    Published:2 Dec 2014
    3.5
    Low

    CVE-2014-5276

    Last Modified: 9 Aug 2014

    Multiple cross-site scripting (XSS) vulnerabilities in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to inject arbitrary web script or HTML via (1) an uploaded profile picture or (2) the edit parameter to profiles/index.php.

    Source:Mike Manzotti
    Published:20 Oct 2014
    6.5
    Medium

    CVE-2014-5275

    Last Modified: 9 Aug 2014

    Multiple SQL injection vulnerabilities in includes/functions.php in Pro Chat Rooms Text Chat Rooms 8.2.0 allow remote authenticated users to execute arbitrary SQL commands via the (1) password, (2) email, or (3) id parameter.

    Source:Mike Manzotti
    Published:20 Oct 2014
    4
    Medium

    CVE-2014-5258

    Last Modified: 25 Sept 2014

    Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:High-Tech Bridge SA
    Published:6 Nov 2014
    10
    Critical

    CVE-2014-5246

    Last Modified: 18 Aug 2014

    The Shenzhen Tenda Technology Tenda A5s router with firmware 3.02.05_CN allows remote attackers to bypass authentication and gain administrator access by setting the admin:language cookie to zh-cn.

    Source:zixian
    Published:22 Aug 2014
    4.3
    Medium

    CVE-2014-5216

    Last Modified: 23 Dec 2014

    Multiple cross-site scripting (XSS) vulnerabilities in NetIQ Access Manager (NAM) 4.x before 4.0.1 HF3 allow remote attackers to inject arbitrary web script or HTML via (1) the location parameter in a dev.Empty action to nps/servlet/webacc, (2) the error parameter to nidp/jsp/x509err.jsp, (3) the lang parameter to sslvpn/applet_agent.jsp, or (4) the secureLoggingServersA parameter to roma/system/cntl, a different issue than CVE-2014-9412.

    Source:SEC Consult
    Published:23 Dec 2014
    10
    Critical

    CVE-2014-5210

    Last Modified: 13 Sept 2017

    The av-centerd SOAP service in AlienVault OSSIM before 4.7.0 allows remote attackers to execute arbitrary commands via a crafted (1) remote_task or (2) get_license request, a different vulnerability than CVE-2014-3804 and CVE-2014-3805.

    Source:James Fitts
    Published:21 Aug 2014
    6.2
    Medium

    CVE-2014-5207

    Last Modified: 9 Oct 2014

    fs/namespace.c in the Linux kernel through 3.16.1 does not properly restrict clearing MNT_NODEV, MNT_NOSUID, and MNT_NOEXEC and changing MNT_ATIME_MASK during a remount of a bind mount, which allows local users to gain privileges, interfere with backups and auditing on systems that had atime enabled, or cause a denial of service (excessive filesystem updating) on systems that had atime disabled via a "mount -o remount" command within a user namespace.

    Source:Andy Lutomirski
    Published:1 Aug 2014
    7.5
    High

    CVE-2014-5201

    Last Modified: 22 Jul 2014

    SQL injection vulnerability in the Gallery Objects plugin 0.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the viewid parameter in a go_view_object action to wp-admin/admin-ajax.php.

    Source:Claudio Viviani
    Published:12 Aug 2014
    7.5
    High

    CVE-2014-5200

    Last Modified: 21 Jan 2016

    SQL injection vulnerability in game_play.php in the FB Gorilla plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Amirh03in
    Published:12 Aug 2014
    6.5
    Medium

    CVE-2014-5194

    Last Modified: 27 Oct 2016

    Static code injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote authenticated users to inject arbitrary PHP code into settings/conf.php via the _word_upper_bound parameter.

    Source:Mike Manzotti
    Published:7 Aug 2014
    4.3
    Medium

    CVE-2014-5193

    Last Modified: 27 Oct 2016

    Cross-site scripting (XSS) vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to inject arbitrary web script or HTML via the category parameter. NOTE: the url parameter vector is already covered by CVE-2014-5082.

    Source:Mike Manzotti
    Published:7 Aug 2014
    7.5
    High

    CVE-2014-5192

    Last Modified: 27 Oct 2016

    SQL injection vulnerability in admin/admin.php in Sphider 1.3.6 allows remote attackers to execute arbitrary SQL commands via the filter parameter.

    Source:Mike Manzotti
    Published:7 Aug 2014
    7.5
    High

    CVE-2014-5189

    Last Modified: 19 Jan 2016

    SQL injection vulnerability in lib/optin/optin_page.php in the Lead Octopus plugin for WordPress allows remote attackers to execute arbitrary SQL commands via the id parameter.

    Source:Amirh03in
    Published:7 Aug 2014
    6.5
    Medium

    CVE-2014-5180

    Last Modified: 21 Jan 2016

    SQL injection vulnerability in the videos page in the HDW Player Plugin (hdw-player-video-player-video-gallery) 2.4.2 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter in the edit action to wp-admin/admin.php.

    Source:Anant Shrivastava
    Published:6 Aug 2014
    5.4
    Medium

    CVE-2014-5144

    Last Modified: 24 Mar 2015

    Cross-site scripting (XSS) vulnerability in Telescope before 0.9.3 allows remote authenticated users to inject arbitrary web script or HTML via crafted markdown.

    Source:shubs
    Published:9 Aug 2017
    8.8
    High

    CVE-2014-5140

    Last Modified: 8 Sept 2014

    The bindReplace function in the query factory in includes/classes/database.php in Loaded Commerce 7 does not properly handle : (colon) characters, which allows remote authenticated users to conduct SQL injection attacks via the First name and Last name fields in the address book.

    Source:Breaking.Technology
    Published:3 Jan 2020
    4.3
    Medium

    CVE-2014-5139

    Last Modified: 12 Apr 2025

    The ssl_set_client_disabled function in t1_lib.c in OpenSSL 1.0.1 before 1.0.1i allows remote SSL servers to cause a denial of service (NULL pointer dereference and client application crash) via a ServerHello message that includes an SRP ciphersuite without the required negotiation of that ciphersuite with the client.

    Published:6 Aug 2014
    7.5
    High

    CVE-2014-5119

    Last Modified: 27 Aug 2014

    Off-by-one error in the __gconv_translit_find function in gconv_trans.c in GNU C Library (aka glibc) allows context-dependent attackers to cause a denial of service (crash) or execute arbitrary code via vectors related to the CHARSET environment variable and gconv transliteration modules.

    Source:taviso & scarybeasts
    Published:14 Jul 2014
    5
    Medium

    CVE-2014-5116

    Last Modified: 16 May 2014

    The cairo_image_surface_get_data function in Cairo 1.10.2, as used in GTK+ and Wireshark, allows context-dependent attackers to cause a denial of service (NULL pointer dereference) via a large string.

    Source:Osanda Malith Jayathissa
    Published:14 Feb 2014
    5
    Medium

    CVE-2014-5115

    Last Modified: 27 Jul 2014

    Absolute path traversal vulnerability in DirPHP 1.0 allows remote attackers to read arbitrary files via a full pathname in the phpfile parameter to index.php.

    Source:black hat
    Published:29 Jul 2014
    7.5
    High

    CVE-2014-5112

    Last Modified: 13 Dec 2016

    maint/modules/home/index.php in Fonality trixbox allows remote attackers to execute arbitrary commands via shell metacharacters in the lang parameter.

    Source:AtT4CKxT3rR0r1ST
    Published:28 Jul 2014
    5
    Medium

    CVE-2014-5111

    Last Modified: 13 Dec 2016

    Multiple directory traversal vulnerabilities in Fonality trixbox allow remote attackers to read arbitrary files via a .. (dot dot) in the lang parameter to (1) home/index.php, (2) asterisk_info/asterisk_info.php, (3) repo/repo.php, or (4) endpointcfg/endpointcfg.php in maint/modules/.

    Source:AtT4CKxT3rR0r1ST
    Published:28 Jul 2014
    7.5
    High

    CVE-2014-5109

    Last Modified: 13 Dec 2016

    SQL injection vulnerability in maint/modules/endpointcfg/endpoint_generic.php in Fonality trixbox allows remote attackers to execute arbitrary SQL commands via the mac parameter in a Submit action.

    Source:AtT4CKxT3rR0r1ST
    Published:28 Jul 2014
    7.5
    High

    CVE-2014-5104

    Last Modified: 28 Jan 2016

    Multiple SQL injection vulnerabilities in ol-commerce 2.1.1 allow remote attackers to execute arbitrary SQL commands via the (1) a_country parameter in a process action to affiliate_signup.php, (2) affiliate_banner_id parameter to affiliate_show_banner.php, (3) country parameter in a process action to create_account.php, or (4) entry_country_id parameter in an edit action to admin/create_account.php.

    Source:AtT4CKxT3rR0r1ST
    Published:28 Jul 2014
    4.3
    Medium

    CVE-2014-5101

    Last Modified: 17 Jan 2016

    Multiple cross-site scripting (XSS) vulnerabilities in WeBid 1.1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) TPL_name, (2) TPL_nick, (3) TPL_email, (4) TPL_year, (5) TPL_address, (6) TPL_city, (7) TPL_prov, (8) TPL_zip, (9) TPL_phone, (10) TPL_pp_email, (11) TPL_authnet_id, (12) TPL_authnet_pass, (13) TPL_worldpay_id, (14) TPL_toocheckout_id, or (15) TPL_moneybookers_email in a first action to register.php or the (16) username parameter in a login action to user_login.php.

    Source:Govind Singh
    Published:25 Jul 2014
    6.8
    Medium

    CVE-2014-5100

    Last Modified: 17 Jul 2014

    Multiple cross-site request forgery (CSRF) vulnerabilities in Omeka before 2.2.1 allow remote attackers to hijack the authentication of administrators for requests that (1) add a new super user account via a request to admin/users/add, (2) insert cross-site scripting (XSS) sequences via the api_key_label parameter to admin/users/api-keys/1, or (3) disable file validation via a request to admin/settings/edit-security.

    Source:LiquidWorm
    Published:25 Jul 2014
    7.5
    High

    CVE-2014-5097

    Last Modified: 22 Jan 2016

    Multiple SQL injection vulnerabilities in Free Reprintables ArticleFR 3.0.4 and earlier allow remote attackers to execute arbitrary SQL commands via the id parameter in a (1) get or (2) set action to rate.php.

    Source:High-Tech Bridge
    Published:22 Aug 2014
    5
    Medium

    CVE-2014-5094

    Last Modified: 2 Aug 2014

    Status2k allows remote attackers to obtain configuration information via a phpinfo action in a request to status/index.php, which calls the phpinfo function.

    Source:Shayan S
    Published:20 Oct 2014
    9.8
    Critical

    CVE-2014-5093

    Last Modified: 2 Aug 2014

    Status2k does not remove the install directory allowing credential reset.

    Source:Shayan S
    Published:10 Jan 2020
    8.8
    High

    CVE-2014-5092

    Last Modified: 2 Aug 2014

    Status2k allows Remote Command Execution in admin/options/editpl.php.

    Source:Shayan S
    Published:10 Jan 2020
    9.8
    Critical

    CVE-2014-5091

    Last Modified: 2 Aug 2014

    A vulnerability exits in Status2K 2.5 Server Monitoring Software via the multies parameter to includes/functions.php, which could let a malicious user execute arbitrary PHP code.

    Source:Shayan S
    Published:7 Feb 2020
    6.5
    Medium

    CVE-2014-5090

    Last Modified: 2 Aug 2014

    admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the Location field in Add Logs in the Admin Panel.

    Source:Shayan S
    Published:6 Aug 2014
    7.5
    High

    CVE-2014-5089

    Last Modified: 2 Aug 2014

    SQL injection vulnerability in admin/options/logs.php in Status2k allows remote authenticated administrators to execute arbitrary SQL commands via the log parameter.

    Source:Shayan S
    Published:6 Aug 2014
    4.3
    Medium

    CVE-2014-5088

    Last Modified: 2 Aug 2014

    Cross-site scripting (XSS) vulnerability in Status2k allows remote attackers to inject arbitrary web script or HTML via the username to login.php.

    Source:Shayan S
    Published:6 Aug 2014
    9.8
    Critical

    CVE-2014-5087

    Last Modified: 2 Aug 2014

    A vulnerability exists in Sphider Search Engine prior to 1.3.6 due to exec calls in admin/spiderfuncs.php, which could let a remote malicious user execute arbitrary code.

    Source:Shayan S
    Published:7 Feb 2020
    8.8
    High

    CVE-2014-5086

    Last Modified: 2 Aug 2014

    A Command Execution vulnerability exists in Sphider Pro, and Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5086 pertains to instances of fwrite in Sphider Pro and Sphider Plus only, but don’t exist in Sphider.

    Source:Shayan S
    Published:10 Feb 2020
    8.8
    High

    CVE-2014-5085

    Last Modified: 2 Aug 2014

    A Command Execution vulnerability exists in Sphider Plus 3.2 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5085 pertains to instances of fwrite in Sphider Plus, but do not exist in either Sphider or Sphider Pro.

    Source:Shayan S
    Published:10 Feb 2020
    8.8
    High

    CVE-2014-5084

    Last Modified: 2 Aug 2014

    A Command Execution vulnerability exists in Sphider Pro 3.2 due to insufficient sanitization of fwrite, which could let a remote malicious user execute arbitrary code. CVE-2014-5084 pertains to instances of fwrite in Sphider Pro only, but do not exist in either Sphider or Sphider Plus.

    Source:Shayan S
    Published:10 Feb 2020
    8.8
    High

    CVE-2014-5083

    Last Modified: 2 Aug 2014

    A Command Execution vulnerability exists in Sphider before 1.3.6 due to insufficient sanitization of fwrite to conf.php, which could let a remote malicious user execute arbitrary code. CVE-2014-5083 pertains to instances of fwrite in Sphider.

    Source:Shayan S
    Published:10 Feb 2020
    7.5
    High

    CVE-2014-5082

    Last Modified: 2 Aug 2014

    Multiple SQL injection vulnerabilities in admin/admin.php in Sphider 1.3.6 and earlier, Sphider Pro, and Sphider-plus allow remote attackers to execute arbitrary SQL commands via the (1) site_id or (2) url parameter.

    Source:Shayan S
    Published:6 Aug 2014
    9.8
    Critical

    CVE-2014-5081

    Last Modified: 2 Aug 2014

    sphider prior to 1.3.6, sphider-pro prior to 3.2, and sphider-plus prior to 3.2 allow authentication bypass

    Source:Shayan S
    Published:10 Jan 2020
    7.1
    High

    CVE-2014-5074

    Last Modified: 22 May 2018

    Siemens SIMATIC S7-1500 CPU devices with firmware before 1.6 allow remote attackers to cause a denial of service (device restart and STOP transition) via crafted TCP packets.

    Source:t4rkd3vilz
    Published:17 Aug 2014
    7.5
    High

    CVE-2014-5073

    Last Modified: 14 Aug 2014

    vmtadmin.cgi in VMTurbo Operations Manager before 4.6 build 28657 allows remote attackers to execute arbitrary commands via shell metacharacters in the fileDate parameter in a DOWN call.

    Source:Metasploit
    Published:29 Aug 2014