|
271261
|
- |
|
chiyu
|
bf-660c
|
Chiyu BF-660C fingerprint access-control devices allow remote attackers to bypass authentication and (1) read or (2) modify communication configuration settings via a request to net.htm, a different …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2871
|
2024-11-21 11:28 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271262
|
- |
|
chiyutw
|
bf-630 bf-630w bf-660c
|
Cross-site scripting (XSS) vulnerability on Chiyu BF-630, BF-630W, and BF-660C fingerprint access-control devices allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2870
|
2024-11-21 11:28 |
2015-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271263
|
- |
|
webservice-dic
|
yoyaku
|
Webservice-DIC yoyaku_v41 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2015-2979
|
2024-11-21 11:28 |
2015-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271264
|
- |
|
webservice-dic
|
yoyaku
|
Webservice-DIC yoyaku_v41 allows remote attackers to bypass authentication and complete a conference-room reservation via unspecified vectors, as demonstrated by an "unintentional reservation."
|
CWE-287
Improper Authentication
|
CVE-2015-2978
|
2024-11-21 11:28 |
2015-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271265
|
- |
|
webservice-dic
|
yoyaku
|
Webservice-DIC yoyaku_v41 allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via unspecified vectors.
|
CWE-20
Improper Input Validation
|
CVE-2015-2977
|
2024-11-21 11:28 |
2015-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271266
|
- |
|
lemon-s_php
|
gazou_bbs_plus
|
LEMON-S PHP Gazou BBS plus before 2.36 allows remote attackers to upload arbitrary HTML documents via vectors involving a crafted image file.
|
CWE-20
Improper Input Validation
|
CVE-2015-2974
|
2024-11-21 11:28 |
2015-07-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271267
|
- |
|
opensuse rubyonrails
|
opensuse rails
|
The (1) jdom.rb and (2) rexml.rb components in Active Support in Ruby on Rails before 4.1.11 and 4.2.x before 4.2.2, when JDOM or REXML is enabled, allow remote attackers to cause a denial of service…
|
NVD-CWE-noinfo
|
CVE-2015-3227
|
2024-11-21 11:28 |
2015-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271268
|
- |
|
rubyonrails
|
ruby_on_rails rails
|
Cross-site scripting (XSS) vulnerability in json/encoding.rb in Active Support in Ruby on Rails 3.x and 4.1.x before 4.1.11 and 4.2.x before 4.2.2 allows remote attackers to inject arbitrary web scri…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3226
|
2024-11-21 11:28 |
2015-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271269
|
- |
|
rack_project opensuse debian
|
rack opensuse debian_linux
|
lib/rack/utils.rb in Rack before 1.5.4 and 1.6.x before 1.6.2, as used with Ruby on Rails 3.x and 4.x and other products, allows remote attackers to cause a denial of service (SystemStackError) via a…
|
CWE-19
Data Processing Errors
|
CVE-2015-3225
|
2024-11-21 11:28 |
2015-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271270
|
- |
|
rubyonrails
|
web_console
|
request.rb in Web Console before 2.1.3, as used with Ruby on Rails 3.x and 4.x, does not properly restrict the use of X-Forwarded-For headers in determining a client's IP address, which allows remote…
|
CWE-284
Improper Access Control
|
CVE-2015-3224
|
2024-11-21 11:28 |
2015-07-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|