|
272241
|
- |
|
unit4
|
prosoft_hrms
|
Cross-site scripting (XSS) vulnerability in Login.aspx in UNIT4 Prosoft HRMS before 8.14.330.43 allows remote attackers to inject arbitrary web script or HTML via the txtUserID parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2082
|
2024-11-21 11:26 |
2015-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272242
|
- |
|
visualware
|
myconnection_server
|
Multiple cross-site scripting (XSS) vulnerabilities in Visualware MyConnection Server 8.2b allow remote attackers to inject arbitrary web script or HTML via the (1) bt, (2) variable, or (3) et parame…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2043
|
2024-11-21 11:26 |
2015-02-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272243
|
- |
|
komodia
|
redirector_sdk
|
The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qustodio for Windows, Atom Security, Inc. StaffCop 5…
|
CWE-310
Cryptographic Issues
|
CVE-2015-2078
|
2024-11-21 11:26 |
2015-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272244
|
- |
|
komodia
|
redirector_sdk
|
The SDK for Komodia Redirector with SSL Digestor, as used in Lavasoft Ad-Aware Web Companion 1.1.885.1766 and Ad-Aware AdBlocker (alpha) 1.3.69.1, Qustodio for Windows, Atom Security, Inc. StaffCop 5…
|
CWE-200
Information Exposure
|
CVE-2015-2077
|
2024-11-21 11:26 |
2015-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272245
|
- |
|
etouch
|
samepage
|
Directory traversal vulnerability in cm/newui/blog/export.jsp in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote authenticated users to read arbitrary files via a .. (dot dot) in the fil…
|
CWE-22
Path Traversal
|
CVE-2015-2071
|
2024-11-21 11:26 |
2015-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272246
|
- |
|
etouch
|
samepage
|
SQL injection vulnerability in eTouch SamePage Enterprise Edition 4.4.0.0.239 allows remote attackers to execute arbitrary SQL commands via the catId parameter to cm/blogrss/feed.
|
CWE-89
SQL Injection
|
CVE-2015-2070
|
2024-11-21 11:26 |
2015-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272247
|
- |
|
woothemes
|
woocommerce
|
Cross-site scripting (XSS) vulnerability in the WooCommerce plugin before 2.2.11 for WordPress allows remote attackers to inject arbitrary web script or HTML via the QUERY_STRING in the wc-reports pa…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2069
|
2024-11-21 11:26 |
2015-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272248
|
- |
|
magmi_project
|
magmi
|
Multiple cross-site scripting (XSS) vulnerabilities in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allow remote attackers to inject arbitrary web script or HTML via the (1) profil…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2068
|
2024-11-21 11:26 |
2015-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272249
|
- |
|
magmi_project
|
magmi
|
Directory traversal vulnerability in web/ajax_pluginconf.php in the MAGMI (aka Magento Mass Importer) plugin for Magento Server allows remote attackers to read arbitrary files via a .. (dot dot) in t…
|
CWE-22
Path Traversal
|
CVE-2015-2067
|
2024-11-21 11:26 |
2015-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272250
|
- |
|
dlguard
|
dlguard
|
SQL injection vulnerability in DLGuard 4.5 allows remote attackers to execute arbitrary SQL commands via the c parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2015-2066
|
2024-11-21 11:26 |
2015-02-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|