|
280141
|
- |
|
ajaxplorer
|
ajaxplorer
|
Directory traversal vulnerability in AjaXplorer 2.0 allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2015-5650
|
2024-11-21 11:33 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280142
|
- |
|
icz
|
matchasns
|
ICZ MATCHA SNS before 1.3.7 allows remote authenticated users to obtain administrative privileges via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5645
|
2024-11-21 11:33 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280143
|
- |
|
icz
|
matchasns
|
The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2015-5644
|
2024-11-21 11:33 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280144
|
- |
|
icz
|
matchasns
|
The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors.
|
CWE-94
Code Injection
|
CVE-2015-5643
|
2024-11-21 11:33 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280145
|
- |
|
icz
|
matchasns
|
Multiple SQL injection vulnerabilities in ICZ MATCHA INVOICE before 2.5.7 allow remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2015-5642
|
2024-11-21 11:33 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280146
|
- |
|
basercms
|
basercms
|
SQL injection vulnerability in baserCMS before 3.0.8 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2015-5641
|
2024-11-21 11:33 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280147
|
- |
|
basercms
|
basercms
|
baserCMS before 3.0.8 allows remote authenticated users to modify arbitrary user settings via a crafted request.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5640
|
2024-11-21 11:33 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280148
|
- |
|
anchorcms
|
anchor_cms
|
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie.
|
CWE-94
Code Injection
|
CVE-2015-5687
|
2024-11-21 11:33 |
2015-10-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280149
|
- |
|
dotclear
|
dotclear
|
Cross-site scripting (XSS) vulnerability in Dotclear before 2.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5651
|
2024-11-21 11:33 |
2015-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280150
|
- |
|
canarylabs
|
trendweb
|
Buffer overflow in Canary Labs Trend Web Server before 9.5.2 allows remote attackers to execute arbitrary code via a crafted TCP packet.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-5653
|
2024-11-21 11:33 |
2015-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|