|
269251
|
- |
|
pivotx
|
pivotx
|
Session fixation vulnerability in fileupload.php in PivotX before 2.3.11 allows remote attackers to hijack web sessions via the sess parameter.
|
NVD-CWE-Other
|
CVE-2015-5458
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269252
|
- |
|
pivotx
|
pivotx
|
PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allows remote attackers to execute arbitrary code by uploading a crafted file, as de…
|
CWE-20
Improper Input Validation
|
CVE-2015-5457
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269253
|
- |
|
pivotx
|
pivotx
|
Cross-site scripting (XSS) vulnerability in the form method in modules/formclass.php in PivotX before 2.3.11 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, related …
|
CWE-79
Cross-site Scripting
|
CVE-2015-5456
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269254
|
- |
|
qualiteam
|
x-cart
|
Cross-site scripting (XSS) vulnerability in X-Cart 4.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to install/.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5455
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269255
|
- |
|
nucleuscms
|
nucleus_cms
|
Cross-site scripting (XSS) vulnerability in Nucleus CMS allows remote attackers to inject arbitrary web script or HTML via the title parameter when adding a new item.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5454
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269256
|
- |
|
watchguard
|
xcs
|
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.
|
CWE-77
Command Injection
|
CVE-2015-5453
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269257
|
- |
|
watchguard
|
xcs
|
SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitrary SQL commands via the sid cookie, as demonstrated by a request to borderpost…
|
CWE-89
SQL Injection
|
CVE-2015-5452
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269258
|
6.5 |
MEDIUM
Network
|
jenkins
|
google_login
|
The Google Login Plugin (versions 1.0 and 1.1) allows malicious anonymous users to authenticate successfully against Jenkins instances that are supposed to be locked down to a particular Google Apps …
|
CWE-287
Improper Authentication
|
CVE-2015-5298
|
2024-11-21 11:32 |
2022-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269259
|
7.5 |
HIGH
Network
|
icedtea-web_project
|
icedtea-web
|
It was discovered that the IcedTea-Web used codebase attribute of the <applet> tag on the HTML page that hosts Java applet in the Same Origin Policy (SOP) checks. As the specified codebase does not h…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2015-5236
|
2024-11-21 11:32 |
2022-07-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269260
|
6.5 |
MEDIUM
Network
|
juniper
|
junos
|
Background For regular, unencrypted FTP traffic, the FTP ALG can inspect the unencrypted control channel and open related sessions for the FTP data channel. These related sessions (gates) are specifi…
|
CWE-326
Inadequate Encryption Strength
|
CVE-2015-5361
|
2024-11-21 11:32 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|