NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
35609 | CVE-2014-8603 | cloner.functions.php in the XCloner plugin 3.1.1 for WordPress and 3.5.1 for Joomla! allows remote administrators to execute arbitrary code via shell metacharacters in the (1) file name when creating a backup or vectors related to the (2) $_CONFIG[tarpath], (3) $exclude, (4) $_CONFIG["tarcompress"], (5) $_CONFIG["filename"], (6) $_CONFIG["exfile_tar"], (7) $_CONFIG[sqldump], (8) $_CONFIG["mysql_host"], (9) $_CONFIG["mysql_pass"], (10) $_CONFIG["mysql_user"], (11) $database_name, or (12) $sqlfile variable. | 2 | 6.5 | Medium | 2017-01-19 | 2015-06-11 | View | |
35865 | CVE-2014-9045 | The FTP backend in user_external in ownCloud Server before 5.0.18 and 6.x before 6.0.6 allows remote attackers to bypass intended authentication requirements via a crafted password. | 2 | 5 | Medium | 2017-01-19 | 2015-02-05 | View | |
37401 | CVE-2013-1153 | Cross-site request forgery (CSRF) vulnerability in the web interface in Cisco Prime Infrastructure allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCue84676. | 2 | 6.8 | Medium | 2017-01-18 | 2013-03-08 | View | |
37657 | CVE-2013-1464 | Cross-site scripting (XSS) vulnerability in assets/player.swf in the Audio Player plugin before 2.0.4.6 for Wordpress allows remote attackers to inject arbitrary web script or HTML via the playerID parameter. | 2 | 4.3 | Medium | 2017-01-18 | 2016-12-07 | View | |
37913 | CVE-2013-1762 | stunnel 4.21 through 4.54, when CONNECT protocol negotiation and NTLM authentication are enabled, does not correctly perform integer conversion, which allows remote proxy servers to execute arbitrary code via a crafted request that triggers a buffer overflow. | 2 | 6.6 | Medium | 2017-01-18 | 2014-01-17 | View |
Page 923 of 17672, showing 5 records out of 88360 total, starting on record 4611, ending on 4615