|
267761
|
6.1 |
MEDIUM
Network
|
testlink
|
testlink
|
Multiple cross-site scripting (XSS) vulnerabilities in TestLink before 1.9.14 allow remote attackers to inject arbitrary web script or HTML via the (1) selected_end_date or (2) selected_start_date pa…
|
CWE-79
Cross-site Scripting
|
CVE-2015-7391
|
2024-11-21 11:36 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267762
|
9.8 |
CRITICAL
Network
|
testlink
|
testlink
|
SQL injection vulnerability in TestLink before 1.9.14 allows remote attackers to execute arbitrary SQL commands via the apikey parameter to lnl.php.
|
CWE-89
SQL Injection
|
CVE-2015-7390
|
2024-11-21 11:36 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267763
|
9.1 |
CRITICAL
Network
|
redhat
|
enterprise_virtualization_manager
|
redhat-support-plugin-rhev in Red Hat Enterprise Virtualization Manager (aka RHEV Manager) before 3.6 allows remote authenticated users with the SuperUser role on any Entity to execute arbitrary comm…
|
CWE-74
Injection
|
CVE-2015-7544
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267764
|
9.8 |
CRITICAL
Network
|
systemd_project
|
systemd
|
Stack-based buffer overflow in the getpwnam and getgrnam functions of the NSS module nss-mymachines in systemd.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-7510
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267765
|
8.8 |
HIGH
Network
|
plone zope
|
plone zope_management_interface
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Zope Management Interface 4.3.7 and earlier, and Plone before 5.x.
|
CWE-352
Origin Validation Error
|
CVE-2015-7293
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267766
|
7.5 |
HIGH
Network
|
plone
|
plone
|
Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.
|
CWE-20
Improper Input Validation
|
CVE-2015-7318
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267767
|
6.8 |
MEDIUM
Network
|
kupu_project plone
|
kupu plone
|
Kupu 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, and 4.2.0 through 4.2.7 allows remote authenticated users to edit Kupu settings.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7317
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267768
|
6.1 |
MEDIUM
Network
|
plone
|
plone
|
Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.x before 4.3.7, and 5.0rc1.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7316
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267769
|
5.9 |
MEDIUM
Network
|
plone
|
plone
|
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registratio…
|
CWE-284
Improper Access Control
|
CVE-2015-7315
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267770
|
4.8 |
MEDIUM
Network
|
zcms_project
|
zcms
|
Cross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages Content Management System 1.1.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7347
|
2024-11-21 11:36 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|