|
272431
|
- |
|
acobot_live_chat_\&_contact_form_project
|
acobot_live_chat_\&_contact_form
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the Acobot Live Chat & Contact Form plugin 2.0 for WordPress allow remote attackers to hijack the authentication of administrators for re…
|
CWE-352
Origin Validation Error
|
CVE-2015-2039
|
2024-11-21 11:26 |
2015-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272432
|
- |
|
piwigo
|
piwigo
|
SQL injection vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote administrators to execute arbitrary SQL commands via the user parameter in the history page to admin.php.
|
CWE-89
SQL Injection
|
CVE-2015-2035
|
2024-11-21 11:26 |
2015-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272433
|
- |
|
piwigo
|
piwigo
|
Cross-site scripting (XSS) vulnerability in the administrative backend in Piwigo before 2.7.4 allows remote attackers to inject arbitrary web script or HTML via the page parameter to admin.php.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2034
|
2024-11-21 11:26 |
2015-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272434
|
- |
|
infoblox
|
netmri
|
Anyterm Daemon in Infoblox Network Automation NetMRI before NETMRI-23483 allows remote attackers to execute arbitrary commands with root privileges via a crafted terminal/anyterm-module request.
|
CWE-287
Improper Authentication
|
CVE-2015-2033
|
2024-11-21 11:26 |
2015-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272435
|
- |
|
google_doc_embedder
|
google_doc_embedder
|
Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the profile parameter in an e…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1879
|
2024-11-21 11:26 |
2015-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272436
|
8.8 |
HIGH
Network
|
hp
|
airwave
|
Aruba AirWave before 8.0.7 allows bypass of a CSRF protection mechanism.
|
CWE-352
Origin Validation Error
|
CVE-2015-1391
|
2024-11-21 11:25 |
2023-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272437
|
6.1 |
MEDIUM
Network
|
hp
|
airwave
|
Aruba AirWave before 8.0.7 allows XSS attacks agsinat an administrator.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1390
|
2024-11-21 11:25 |
2023-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272438
|
6.5 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
JetBrains TeamCity 8 and 9 before 9.0.2 allows bypass of account-creation restrictions via a crafted request because the required request data can be deduced by reading HTML and JavaScript files that…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2015-1313
|
2024-11-21 11:25 |
2023-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272439
|
8.8 |
HIGH
Network
|
atutor
|
atutor
|
Multiple cross-site request forgery (CSRF) vulnerabilities in ATutor 2.2 allow remote attackers to hijack the authentication of administrators for requests that (1) create an administrator account vi…
|
CWE-352
Origin Validation Error
|
CVE-2015-1583
|
2024-11-21 11:25 |
2020-03-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272440
|
9.8 |
CRITICAL
Network
|
jakweb
|
gecko_cms
|
JAKWEB Gecko CMS has Multiple Input Validation Vulnerabilities
|
CWE-20
Improper Input Validation
|
CVE-2015-1425
|
2024-11-21 11:25 |
2020-02-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|