|
272761
|
- |
|
aas9
|
zerocms
|
SQL injection vulnerability in views/zero_transact_user.php in the administrative backend in ZeroCMS 1.3.3, 1.3.2, and earlier allows remote authenticated users to execute arbitrary SQL commands via …
|
CWE-89
SQL Injection
|
CVE-2015-1442
|
2024-11-21 11:25 |
2015-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272762
|
- |
|
mcafee
|
data_loss_prevention_endpoint
|
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1305
|
2024-11-21 11:25 |
2015-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272763
|
- |
|
ansible
|
tower
|
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connection to socket.io/1/.
|
CWE-200
Information Exposure
|
CVE-2015-1482
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272764
|
- |
|
ansible
|
tower
|
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1481
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272765
|
- |
|
manageengine
|
servicedesk_plus
|
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a dire…
|
CWE-200
Information Exposure
|
CVE-2015-1480
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272766
|
- |
|
zohocorp
|
servicedesk_plus
|
SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to execute arbitrary SQL commands via …
|
CWE-89
SQL Injection
|
CVE-2015-1479
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272767
|
- |
|
cmsjunkie
|
j-classifiedsmanager
|
Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the view parameter to /classifi…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1478
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272768
|
- |
|
cmsjunkie
|
j-classifiedsmanager
|
SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewad task to classifieds/…
|
CWE-89
SQL Injection
|
CVE-2015-1477
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272769
|
- |
|
ecommercemajor_project
|
ecommercemajor
|
Multiple SQL injection vulnerabilities in xlinkerz ecommerceMajor allow remote attackers to execute arbitrary SQL commands via the (1) productbycat parameter to product.php, or (2) username or (3) pa…
|
CWE-89
SQL Injection
|
CVE-2015-1476
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272770
|
- |
|
mylittleforum
|
my_little_forum
|
Multiple cross-site scripting (XSS) vulnerabilities in my little forum 2.3.3, 2.2, and 1.7 allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) category parameter to …
|
CWE-79
Cross-site Scripting
|
CVE-2015-1475
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|