|
268421
|
8.1 |
HIGH
Network
|
salesagility
|
suitecrm
|
SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code.
|
CWE-362
Race Condition
|
CVE-2015-5947
|
2024-11-21 11:34 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268422
|
8.8 |
HIGH
Network
|
phpfilemanager_project
|
phpfilemanager
|
phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.
|
CWE-78
OS Command
|
CVE-2015-5958
|
2024-11-21 11:34 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268423
|
7.8 |
HIGH
Local
|
sugarcrm
|
sugarcrm
|
Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.
|
CWE-184
Incomplete Blacklist
|
CVE-2015-5946
|
2024-11-21 11:34 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268424
|
7.8 |
HIGH
Local
|
redhat
|
ansible
|
The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.
|
CWE-59
Link Following
|
CVE-2015-6240
|
2024-11-21 11:34 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268425
|
6.1 |
MEDIUM
Network
|
opsview
|
opsview
|
Opsview before 2015-11-06 has XSS via SNMP.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6035
|
2024-11-21 11:34 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268426
|
8.8 |
HIGH
Network
|
castlerock
|
snmpc
|
Castle Rock Computing SNMPc before 2015-12-17 has SQL injection via the sc parameter.
|
CWE-89
SQL Injection
|
CVE-2015-6028
|
2024-11-21 11:34 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268427
|
6.1 |
MEDIUM
Network
|
castlerock
|
snmpc
|
Castle Rock Computing SNMPc before 2015-12-17 has XSS via SNMP.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6027
|
2024-11-21 11:34 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268428
|
6.1 |
MEDIUM
Network
|
spiceworks
|
desktop
|
Spiceworks Desktop before 2015-12-01 has XSS via an SNMP response.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6021
|
2024-11-21 11:34 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268429
|
9.8 |
CRITICAL
Network
|
netcommwireless
|
hspa_3g10wve_firmware
|
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote authenticated users to execute arbitrary commands via shell metacharacters in…
|
CWE-77
Command Injection
|
CVE-2015-6024
|
2024-11-21 11:34 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268430
|
7.3 |
HIGH
Network
|
netcommwireless
|
hspa_3g10wve_firmware
|
ping.cgi in NetCommWireless HSPA 3G10WVE wireless routers with firmware before 3G10WVE-L101-S306ETS-C01_R05 allows remote attackers to bypass intended access restrictions via a direct request. NOTE:…
|
CWE-284
Improper Access Control
|
CVE-2015-6023
|
2024-11-21 11:34 |
2017-02-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|