|
265051
|
6.5 |
MEDIUM
Network
|
misys
|
fusioncapital_opics_plus
|
Multiple SQL injection vulnerabilities in Misys FusionCapital Opics Plus allow remote authenticated users to execute arbitrary SQL commands via the (1) ID or (2) Branch parameter.
|
CWE-89
SQL Injection
|
CVE-2016-5653
|
2024-11-21 11:54 |
2016-07-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265052
|
8.1 |
HIGH
Network
|
redhat hp oracle apache
|
enterprise_linux_desktop enterprise_linux_server_aus enterprise_linux_workstation enterprise_linux_server_tus enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_serv…
|
Apache Tomcat 7.x through 7.0.70 and 8.x through 8.5.4, when the CGI Servlet is enabled, follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted cli…
|
CWE-284
Improper Access Control
|
CVE-2016-5388
|
2024-11-21 11:54 |
2016-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265053
|
8.1 |
HIGH
Network
|
apache hp oracle fedoraproject redhat debian canonical opensuse
|
http_server system_management_homepage enterprise_manager_ops_center solaris linux communications_user_data_repository fedora jboss_web_server jboss_enterprise_web_server j…
|
The Apache HTTP Server through 2.4.23 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, wh…
|
NVD-CWE-noinfo
|
CVE-2016-5387
|
2024-11-21 11:54 |
2016-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265054
|
8.1 |
HIGH
Network
|
fedoraproject oracle redhat golang
|
fedora linux enterprise_linux_server_aus enterprise_linux_server enterprise_linux_server_eus go
|
The net/http package in Go through 1.6 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client da…
|
CWE-284
Improper Access Control
|
CVE-2016-5386
|
2024-11-21 11:54 |
2016-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265055
|
8.1 |
HIGH
Network
|
oracle fedoraproject hp php redhat debian opensuse drupal
|
enterprise_manager_ops_center communications_user_data_repository linux fedora storeever_msl6480_tape_library_firmware system_management_homepage php enterprise_linux_desktop …
|
PHP through 7.0.8 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY envi…
|
CWE-601
Open Redirect
|
CVE-2016-5385
|
2024-11-21 11:54 |
2016-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265056
|
8.8 |
HIGH
Network
|
accela
|
civic_platform_citizen_access_portal
|
Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execute arbitrary code via modified _EventArgument and …
|
CWE-284
Improper Access Control
|
CVE-2016-5661
|
2024-11-21 11:54 |
2016-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265057
|
6.1 |
MEDIUM
Network
|
accela
|
civic_platform
|
Cross-site scripting (XSS) vulnerability in AttachmentsList.aspx in Accela Civic Platform Citizen Access portal allows remote attackers to inject arbitrary web script or HTML via the iframeid paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2016-5660
|
2024-11-21 11:54 |
2016-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265058
|
8.8 |
HIGH
Network
|
libbpg_project
|
libbpg
|
The restore_tqb_pixels function in libbpg 0.9.5 through 0.9.7 mishandles the transquant_bypass_enable_flag value, which allows remote attackers to execute arbitrary code or cause a denial of service …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5637
|
2024-11-21 11:54 |
2016-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265059
|
5.5 |
MEDIUM
Local
|
symantec
|
client_intrusion_detection_system
|
The Client Intrusion Detection System (CIDS) driver before 15.0.6 in Symantec Endpoint Protection (SEP) and before 15.1.2 in Norton Security allows remote attackers to cause a denial of service (memo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-5308
|
2024-11-21 11:54 |
2016-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265060
|
7.5 |
HIGH
Network
|
opensuse phpmyadmin
|
leap opensuse phpmyadmin
|
The Transformation implementation in phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not use the no-referrer Content Security Policy (CSP) protection mechanism, …
|
CWE-200
Information Exposure
|
CVE-2016-5739
|
2024-11-21 11:54 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|