Skybox Platform versions 7.0.611 and below suffer from code execution, remote SQL injection, cross site scripting, and directory traversal vulnerabilities.
d2a34290d02d3f2013ecd41c823081fe86b61aaf79b73808107e70eb70589040
Shopizer version 1.1.5 suffers from authentication and authorization bypass vulnerabilities and also has a hardcoded default encryption key.
3151b133fe3a990ab5b4430efd7f97f3a1ea24619f03afeb2acc81fee40ad78c
Oracle WebCenter Sites Satellite Server versions 7.6.0 Patch1, 7.6.2, 11.1.1.6.0, and 11.1.1.6.1 suffer from HTTP header injection and cache poisoning vulnerabilities.
b211d5ba79c2e4506fc8c437bbb356031d7bc5df5b5dceb6705801d00369973b
ELBA 5 version 5.5.0 R00006 build 0796 suffers from remote SQL injection, unencrypted password storage, default credential use, and buffer overflow vulnerabilities.
c54c52eb248b249e3839005d54ed6fc24cfcb0ceb545a988aa2b640cf7a7f90c
Unirgy uStoreLocator Magento extension versions 2.0.0 and below suffer from a remote SQL injection vulnerability.
6e4abf5adbbbb92200ba426805348f157961e9a3deb1da91504764ab97eddb22
Magento eCommerce platform uses a vulnerable version of Zend framework which is prone to XML eXternal Entity Injection attacks. The SimpleXMLElement class of Zend framework (SimpleXML PHP extension) is used in an insecure way to parse XML data. External entities can be specified by adding a specific DOCTYPE element to XML-RPC requests. By exploiting this vulnerability an application may be coerced to open arbitrary files and/or TCP connections.
89d448f5823f6c330e5a4b53e23014a5b1fe003dd4087081ff3c078b9e4d3271
Zend Framework versions 1.11.11, 1.12.0 RC1, and 2.0.0 beta4 suffer from remote file disclosure via an XXE injection vulnerability.
c3bbf3eadcb973470c3821625d1d343feeac92ba6e51810c867cb80422569cac
OpenOffice.org includes the customized libwpd version 0.8.8 library for parsing WordPerfect documents. The used version of the libwpd library suffers from a memory overwrite vulnerability when reading a specially crafted WPD file. Successful exploitation of this vulnerability could result in an arbitrary code execution within the OpenOffice.org software suite.
c0fbf3513a8c6f3a2d74cceeb3b60aa04aa8253399451b37f5db876426268ecb
OpenOffice.org versions 3.3 and 3.4 Beta suffer from a memory overwrite vulnerability.
8835dab05febe30ee3df1bb4c48de2c02504156f840dc2d1d9c1e0014179f8ce