|
272731
|
- |
|
gnu opensuse
|
grep opensuse
|
The bmexec_trans function in kwset.c in grep 2.19 through 2.21 allows local users to cause a denial of service (out-of-bounds heap read and crash) via crafted input when using the -F option.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-1345
|
2024-11-21 11:25 |
2015-02-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272732
|
- |
|
web-dorado
|
spider_facebook
|
Multiple cross-site scripting (XSS) vulnerabilities in the Spider Facebook plugin before 1.0.11 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the appid parameter…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1582
|
2024-11-21 11:25 |
2015-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272733
|
- |
|
mobile_domain_project
|
mobile_domain
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the Mobile Domain plugin 1.5.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) …
|
CWE-352
Origin Validation Error
|
CVE-2015-1581
|
2024-11-21 11:25 |
2015-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272734
|
- |
|
redirection_project
|
redirection
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the Redirection Page plugin 1.2 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1)…
|
CWE-352
Origin Validation Error
|
CVE-2015-1580
|
2024-11-21 11:25 |
2015-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272735
|
- |
|
elegant_themes
|
divi
|
Directory traversal vulnerability in the Elegant Themes Divi theme for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the img parameter in a revslider_show_image acti…
|
CWE-22
Path Traversal
|
CVE-2015-1579
|
2024-11-21 11:25 |
2015-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272736
|
- |
|
yuba
|
u5cms
|
Multiple open redirect vulnerabilities in u5CMS before 3.9.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the (1) pidvesa cookie to u5admi…
|
NVD-CWE-Other
|
CVE-2015-1578
|
2024-11-21 11:25 |
2015-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272737
|
- |
|
yuba
|
u5cms
|
Directory traversal vulnerability in u5admin/deletefile.php in u5CMS before 3.9.4 allows remote attackers to write to arbitrary files via a (1) .. (dot dot) or (2) full pathname in the f parameter.
|
CWE-22
Path Traversal
|
CVE-2015-1577
|
2024-11-21 11:25 |
2015-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272738
|
- |
|
yuba
|
u5cms
|
Multiple SQL injection vulnerabilities in u5CMS before 3.9.4 allow remote attackers to execute arbitrary SQL commands via the name parameter to (1) copy2.php, (2) localize.php, (3) metai.php, (4) nc.…
|
CWE-89
SQL Injection
|
CVE-2015-1576
|
2024-11-21 11:25 |
2015-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272739
|
- |
|
yuba
|
u5cms
|
Multiple cross-site scripting (XSS) vulnerabilities in u5CMS before 3.9.4 allow remote attackers to inject arbitrary web script or HTML via the (1) c, (2) i, (3) l, or (4) p parameter to index.php; t…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1575
|
2024-11-21 11:25 |
2015-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272740
|
- |
|
redaxscript
|
redaxscript
|
SQL injection vulnerability in the search_post function in includes/search.php in Redaxscript before 2.3.0 allows remote attackers to execute arbitrary SQL commands via the search_terms parameter.
|
CWE-89
SQL Injection
|
CVE-2015-1518
|
2024-11-21 11:25 |
2015-02-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|