CVE-2014-0808

CRITICAL Year: 2014
CVSS v3 Score
9.1
Critical
CVSS v2 Score
5.0
Medium

Vulnerability Description

Authorization bypass through user-controlled key issue exists in EC-CUBE 2.11.0 through 2.12.2 and EC-Orange systems deployed before June 29th, 2015. If this vulnerability is exploited, a user of the affected shopping website may obtain other users' information by sending a crafted HTTP request.

CVSS:10.0(Critical)

Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection.This issue affects Mobuy Online Machinery Monito...

CVSS:10.0(Critical)

Authorization Bypass Through User-Controlled SQL Primary Key vulnerability in BSS Software Mobuy Online Machinery Monitoring Panel allows SQL Injection.This issue affects Mobuy Online Machinery Monito...

CVSS:5.5(Medium)

SQL-Injection in Harbor allows priviledge users to leak the task IDs

CVSS:2.7(Low)

Zulip is an open-source team collaboration tool. The API for deleting an organization export is supposed to be restricted to organization administrators, but its handler failed to check that the field...

CVSS:2.7(Low)

Zulip is an open-source team collaboration tool. The API for deleting an organization custom profile field is supposed to be restricted to organization administrators, but its handler failed to check ...