|
275991
|
- |
|
fedoraproject phpmyadmin
|
fedora phpmyadmin
|
libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a…
|
CWE-200
Information Exposure
|
CVE-2015-2206
|
2024-11-21 11:27 |
2015-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275992
|
- |
|
google
|
chrome
|
Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which ma…
|
CWE-19
Data Processing Errors
|
CVE-2015-2239
|
2024-11-21 11:27 |
2015-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275993
|
- |
|
canonical google
|
ubuntu_linux chrome v8
|
Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 41.0.2272.76, allow attackers to cause a denial of service or possibly have other impact via unknown…
|
NVD-CWE-noinfo
|
CVE-2015-2238
|
2024-11-21 11:27 |
2015-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275994
|
- |
|
ninjaforms
|
ninja_forms
|
Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 …
|
CWE-79
Cross-site Scripting
|
CVE-2015-2220
|
2024-11-21 11:27 |
2015-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275995
|
- |
|
magic_hills
|
wonderplugin_audio_player
|
Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow remote attackers …
|
CWE-79
Cross-site Scripting
|
CVE-2015-2218
|
2024-11-21 11:27 |
2015-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275996
|
- |
|
photocati_media
|
photocrati
|
SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to execute arbitrary SQL commands via the prod_id parameter.
|
CWE-89
SQL Injection
|
CVE-2015-2216
|
2024-11-21 11:27 |
2015-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275997
|
- |
|
services_single_sign-on_server_helper_project
|
services_single_sign-on_server_helper
|
Open redirect vulnerability in the Services single sign-on server helper (services_sso_server_helper) module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct ph…
|
NVD-CWE-Other
|
CVE-2015-2215
|
2024-11-21 11:27 |
2015-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275998
|
- |
|
netcat
|
netcat
|
NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.
|
CWE-200
Information Exposure
|
CVE-2015-2214
|
2024-11-21 11:27 |
2015-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275999
|
- |
|
dlguard
|
dlguard
|
DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php.
|
CWE-200
Information Exposure
|
CVE-2015-2209
|
2024-11-21 11:27 |
2015-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276000
|
5.5 |
MEDIUM
Local
|
xaviershay-dm-rails_porject
|
xaviershay-dm-rails
|
The xaviershay-dm-rails gem 0.10.3.8 for Ruby allows local users to discover MySQL credentials by listing a process and its arguments.
|
NVD-CWE-noinfo
|
CVE-2015-2179
|
2024-11-21 11:26 |
2023-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|