3722 vulnerabilidades · ⚡ Nuclei Orden: CVSS EPSS Año ID
CVE-2014-5258
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
81.2%
2014 1 PoC

Directory traversal vulnerability in showTempFile.php in webEdition CMS before 6.3.9.0 Beta allows remote authenticated users to read arbitrary files via a .. (dot dot) in the file parameter.

CVE-2014-9609
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
31.2%
2014 1 PoC

Directory traversal vulnerability in webadmin/reporter/view_server_log.php in Netsweeper before 3.1.10, 4.0.x before 4.0.9, and 4.1.x before 4.1.2 allows remote attackers to list directory contents via a .. (dot dot) in the log parameter in a stats action.

CVE-2014-3704
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.2%
2014 12 PoCs

The expandArguments function in the database abstraction API in Drupal core 7.x before 7.32 does not properly construct prepared statements, which allows remote attackers to conduct SQL injection attacks via an array containing crafted keys.

CVE-2014-10037
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
65.4%
2014 0 PoCs

Directory traversal vulnerability in DomPHP 0.83 and earlier allows remote attackers to have unspecified impact via a .. (dot dot) in the url parameter to photoalbum/index.php.

CVE-2014-9119
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
51.1%
2014 2 PoCs

Directory traversal vulnerability in download.php in the DB Backup plugin 4.5 and earlier for Wordpress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

CVE-2014-5368
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
48.3%
2014 1 PoC

Directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Source Control (wp-source-control) plugin 3.0.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter.

CVE-2014-8799
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
91.1%
2014 1 PoC

Directory traversal vulnerability in the dp_img_resize function in php/dp-functions.php in the DukaPress plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the src parameter to lib/dp_image.php.

CVE-2014-4942
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.5%
2014 0 PoCs

The EasyCart (wp-easycart) plugin before 2.0.6 for WordPress allows remote attackers to obtain configuration information via a direct request to inc/admin/phpinfo.php, which calls the phpinfo function.

CVE-2014-8682
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
76.9%
2014 3 PoCs

Multiple SQL injection vulnerabilities in Gogs (aka Go Git Service) 0.3.1-9 through 0.5.x before 0.5.6.1105 Beta allow remote attackers to execute arbitrary SQL commands via the q parameter to (1) api/v1/repos/search, which is not properly handled in models/repo.go, or (2) api/v1/users/search, which is not properly handled in models/user.go.

CVE-2014-4210
Software Genérico Database ⚡ nuclei
N/A
UNKNOWN
EPSS
94.1%
2014 6 PoCs

Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 10.0.2.0 and 10.3.6.0 allows remote attackers to affect confidentiality via vectors related to WLS - Web Services.

CVE-2014-2383
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
54.9%
2014 3 PoCs

dompdf.php in dompdf before 0.6.1, when DOMPDF_ENABLE_PHP is enabled, allows context-dependent attackers to bypass chroot protections and read arbitrary files via a PHP protocol and wrappers in the input_file parameter, as demonstrated by a php://filter/read=convert.base64-encode/resource in the input_file parameter.

CVE-2014-4539
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
1.6%
2014 0 PoCs

Cross-site scripting (XSS) vulnerability in the Movies plugin 0.6 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.

CVE-2014-9444
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.3%
2014 2 PoCs

Cross-site scripting (XSS) vulnerability in the Frontend Uploader plugin 0.9.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the errors[fu-disallowed-mime-type][0][name] parameter to the default URI.

CVE-2014-4535
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
3.8%
2014 0 PoCs

Cross-site scripting (XSS) vulnerability in the Import Legacy Media plugin 0.1 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the filename parameter to getid3/demos/demo.mimeonly.php.

CVE-2014-3744
Software Genérico General ⚡ nuclei
N/A
UNKNOWN
EPSS
78.2%
2014 0 PoCs

Directory traversal vulnerability in the st module before 0.2.5 for Node.js allows remote attackers to read arbitrary files via a %2e%2e (encoded dot dot) in an unspecified path.

CVE-2014-1203
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
56.1%
2014 0 PoCs

The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php.

CVE-2014-4561
Software Genérico Web Windows ⚡ nuclei
N/A
UNKNOWN
EPSS
8.5%
2014 0 PoCs

The ultimate-weather plugin 1.0 for WordPress has XSS

CVE-2014-2962
Software Genérico Networking ⚡ nuclei
N/A
UNKNOWN
EPSS
88.9%
2014 2 PoCs

Absolute path traversal vulnerability in the webproc cgi module on the Belkin N150 F9K1009 v1 router with firmware before 1.00.08 allows remote attackers to read arbitrary files via a full pathname in the getpage parameter.

CVE-2014-2323
Software Genérico Web Database ⚡ nuclei
N/A
UNKNOWN
EPSS
90.4%
2014 0 PoCs

SQL injection vulnerability in mod_mysql_vhost.c in lighttpd before 1.4.35 allows remote attackers to execute arbitrary SQL commands via the host name, related to request_check_hostname.

CVE-2014-9607
Software Genérico Web ⚡ nuclei
N/A
UNKNOWN
EPSS
9.0%
2014 1 PoC

Cross-site scripting (XSS) vulnerability in remotereporter/load_logfiles.php in Netsweeper 4.0.3 and 4.0.4 allows remote attackers to inject arbitrary web script or HTML via the url parameter.