|
268891
|
5.4 |
MEDIUM
Network
|
plot
|
plotly
|
Cross-site scripting (XSS) vulnerability in the Plotly plugin before 1.0.3 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via a post.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5484
|
2024-11-21 11:33 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268892
|
7.8 |
HIGH
Local
|
sis
|
xgi_vga_display_manager
|
Silicon Integrated Systems XGI WindowsXP Display Manager (aka XGI VGA Driver Manager and VGA Display Manager) 6.14.10.1090 allows local users to gain privileges via a crafted 0x96002404 IOCTL call.
|
CWE-269
Improper Privilege Management
|
CVE-2015-5466
|
2024-11-21 11:33 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268893
|
6.5 |
MEDIUM
Network
|
zenphoto
|
zenphoto
|
Cross-site request forgery (CSRF) vulnerability in admin.php in Zenphoto before 1.4.9 allows remote attackers to hijack the authentication of admin users for requests that may cause a denial of servi…
|
CWE-352
Origin Validation Error
|
CVE-2015-5595
|
2024-11-21 11:33 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268894
|
6.1 |
MEDIUM
Network
|
zenphoto
|
zenphoto
|
The sanitize_string function in Zenphoto before 1.4.9 does not properly sanitize HTML tags, which allows remote attackers to perform a cross-site scripting (XSS) attack by wrapping a payload in "<<sc…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5593
|
2024-11-21 11:33 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268895
|
6.1 |
MEDIUM
Network
|
zenphoto
|
zenphoto
|
Incomplete blacklist in sanitize_string in Zenphoto before 1.4.9 allows remote attackers to conduct cross-site scripting (XSS) attacks.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5592
|
2024-11-21 11:33 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268896
|
7.2 |
HIGH
Network
|
zenphoto
|
zenphoto
|
SQL injection vulnerability in Zenphoto before 1.4.9 allow remote administrators to execute arbitrary SQL commands.
|
CWE-89
SQL Injection
|
CVE-2015-5591
|
2024-11-21 11:33 |
2020-01-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268897
|
6.5 |
MEDIUM
Network
|
openstack redhat debian
|
designate enterprise_linux_openstack_platform debian_linux
|
Designate does not enforce the DNS protocol limit concerning record set sizes
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2015-5694
|
2024-11-21 11:33 |
2019-11-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268898
|
8.8 |
HIGH
Network
|
edx
|
edx-platform
|
edx-platform before 2015-07-20 allows code execution by privileged users because the course import endpoint mishandles .tar.gz files.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-5601
|
2024-11-21 11:33 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268899
|
6.1 |
MEDIUM
Network
|
axiomsl
|
axiom
|
AxiomSL's Axiom Google Web Toolkit module 9.5.3 and earlier allows remote attackers to inject HTML into the scoping dashboard features.
|
CWE-74
Injection
|
CVE-2015-5462
|
2024-11-21 11:33 |
2019-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268900
|
9.8 |
CRITICAL
Network
|
axiomsl
|
axiom
|
AxiomSL's Axiom java applet module (used for editing uploaded Excel files and associated Java RMI services) 9.5.3 and earlier allows remote attackers to (1) access data of other basic users through a…
|
CWE-285
Improper Authorization
|
CVE-2015-5463
|
2024-11-21 11:33 |
2019-04-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|