|
271211
|
- |
|
sysaid
|
sysaid
|
SysAid Help Desk before 15.2 does not properly restrict access to certain functionality, which allows remote attackers to (1) create administrator accounts via a crafted request to /createnewaccount …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2993
|
2024-11-21 11:28 |
2015-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271212
|
- |
|
f21
|
jwt
|
JWT.php in F21 JWT before 2.0 allows remote attackers to bypass signature verification via crafted tokens.
|
CWE-20
Improper Input Validation
|
CVE-2015-2951
|
2024-11-21 11:28 |
2015-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271213
|
- |
|
open_explorer_beta_project
|
open_explorer_beta
|
Directory traversal vulnerability in the Brandon Bowles Open Explorer application before 0.254 Beta for Android allows remote attackers to write to arbitrary files via a crafted filename.
|
CWE-22
Path Traversal
|
CVE-2015-2950
|
2024-11-21 11:28 |
2015-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271214
|
- |
|
apache
|
sling_servlets_post sling_api
|
Multiple cross-site scripting (XSS) vulnerabilities in Apache Sling API before 2.2.2 and Apache Sling Servlets Post before 2.1.2 allow remote attackers to inject arbitrary web script or HTML via the …
|
CWE-79
Cross-site Scripting
|
CVE-2015-2944
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271215
|
- |
|
moodle
|
moodle
|
files/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not consider the moodle/user:manageownfiles capability before approving a private-f…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3181
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271216
|
- |
|
moodle
|
moodle
|
lib/navigationlib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to obtain sensitive course-structure information by le…
|
CWE-200
Information Exposure
|
CVE-2015-3180
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271217
|
- |
|
moodle
|
moodle
|
login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote authenticated users to bypass intended login restrictions by leveraging access…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-3179
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271218
|
- |
|
moodle
|
moodle
|
Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows re…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3178
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271219
|
- |
|
moodle
|
moodle
|
Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sen…
|
CWE-17
Code
|
CVE-2015-3177
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271220
|
- |
|
moodle
|
moodle
|
The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name in…
|
CWE-200
Information Exposure
|
CVE-2015-3176
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|