|
268041
|
5.4 |
MEDIUM
Network
|
vindula
|
vindula
|
Cross-site scripting (XSS) vulnerability in Vindula 1.9.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6959
|
2024-11-21 11:35 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268042
|
6.1 |
MEDIUM
Network
|
igcb
|
intellect_digital_core
|
Cross-site scripting (XSS) vulnerability in Intellect Design Arena Intellect Core banking software.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6540
|
2024-11-21 11:35 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268043
|
7.8 |
HIGH
Local
|
paloaltonetworks
|
pan-os
|
Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file.
|
CWE-94
Code Injection
|
CVE-2015-6531
|
2024-11-21 11:35 |
2017-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268044
|
8.1 |
HIGH
Network
|
pgbouncer
|
pgbouncer
|
PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.
|
CWE-287
Improper Authentication
|
CVE-2015-6817
|
2024-11-21 11:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268045
|
7.5 |
HIGH
Network
|
huawei
|
wlan_acu2_firmware wlan_ac6005_firmware wlan_ac6605_firmware
|
The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote attackers to obtain sensitive information by leveraging failure to restrict proces…
|
CWE-200
Information Exposure
|
CVE-2015-6586
|
2024-11-21 11:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268046
|
8.8 |
HIGH
Network
|
wolfcms
|
wolf_cms
|
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" …
|
CWE-20
Improper Input Validation
|
CVE-2015-6568
|
2024-11-21 11:35 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268047
|
8.8 |
HIGH
Network
|
wolfcms
|
wolf_cms
|
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exp…
|
CWE-20
Improper Input Validation
|
CVE-2015-6567
|
2024-11-21 11:35 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268048
|
9.8 |
CRITICAL
Network
|
inspircd debian
|
inspircd debian_linux
|
Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This issue exists as an additional issue from an incomplet…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6674
|
2024-11-21 11:35 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268049
|
5.9 |
MEDIUM
Network
|
edx
|
edx-platform
|
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveragi…
|
CWE-200
Information Exposure
|
CVE-2015-6671
|
2024-11-21 11:35 |
2017-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268050
|
6.1 |
MEDIUM
Network
|
puppet
|
puppet_enterprise
|
Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the string parameter.
|
CWE-601
Open Redirect
|
CVE-2015-6501
|
2024-11-21 11:35 |
2017-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|