|
270261
|
- |
|
eliacom
|
enhanced_sql_portal
|
Cross-site scripting (XSS) vulnerability in Enhanced SQL Portal 5.0.7961 allows remote attackers to inject arbitrary web script or HTML via the id parameter to iframe.php.
|
CWE-79
Cross-site Scripting
|
CVE-2015-4660
|
2024-11-21 11:31 |
2015-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270262
|
- |
|
labsmedia
|
clickheat
|
Cross-site request forgery (CSRF) vulnerability in ClickHeat 1.14 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator passwor…
|
CWE-352
Origin Validation Error
|
CVE-2015-4659
|
2024-11-21 11:31 |
2015-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270263
|
- |
|
milw0rm_project
|
milw0rm_clone_script
|
Multiple SQL injection vulnerabilities in admin/login.php in Milw0rm Clone Script 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) usr or (2) pwd parameter.
|
CWE-89
SQL Injection
|
CVE-2015-4658
|
2024-11-21 11:31 |
2015-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270264
|
- |
|
mailbird
|
mailbird
|
Cross-site scripting (XSS) vulnerability in Mailbird 2.0.16.0 and earlier allows remote attackers to inject arbitrary web script or HTML via an e-mail message body with a crafted URL.
|
CWE-79
Cross-site Scripting
|
CVE-2015-4657
|
2024-11-21 11:31 |
2015-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270265
|
- |
|
synology
|
photo_station
|
Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station before 6.3-2945 allow remote attackers to inject arbitrary web script or HTML via the (1) success parameter to login.php …
|
CWE-79
Cross-site Scripting
|
CVE-2015-4656
|
2024-11-21 11:31 |
2015-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270266
|
- |
|
synology
|
diskstation_manager
|
Cross-site scripting (XSS) vulnerability in Synology DiskStation Manager (DSM) before 5.2-5565 Update 1 allows remote attackers to inject arbitrary web script or HTML via the "compound" parameter to …
|
CWE-79
Cross-site Scripting
|
CVE-2015-4655
|
2024-11-21 11:31 |
2015-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270267
|
- |
|
joomla
|
joomla\!
|
SQL injection vulnerability in the EQ Event Calendar component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter to eqfullevent.
|
CWE-89
SQL Injection
|
CVE-2015-4654
|
2024-11-21 11:31 |
2015-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270268
|
- |
|
alcatel-lucent
|
cellpipe_7130_router_firmware
|
Cross-site scripting (XSS) vulnerability in the Alcatel-Lucent CellPipe 7130 router with firmware 1.0.0.20h.HOL allows remote attackers to inject arbitrary web script or HTML via the "Custom applicat…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4587
|
2024-11-21 11:31 |
2015-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270269
|
- |
|
opsview
|
opsview
|
Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) crafted check plugin, the (2) description in a…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4420
|
2024-11-21 11:31 |
2015-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270270
|
- |
|
limesurvey
|
limesurvey
|
SQL injection vulnerability in application/controllers/admin/questiongroups.php in LimeSurvey before 2.06+ Build 150618 allows remote authenticated administrators to execute arbitrary SQL commands vi…
|
CWE-89
SQL Injection
|
CVE-2015-4628
|
2024-11-21 11:31 |
2015-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|