|
270141
|
9.8 |
CRITICAL
Network
|
metalgenix
|
genixcms
|
Multiple SQL injection vulnerabilities in inc/lib/User.class.php in MetalGenix GeniXCMS before 0.0.3-patch allow remote attackers to execute arbitrary SQL commands via the (1) email parameter or (2) …
|
CWE-89
SQL Injection
|
CVE-2015-3933
|
2024-11-21 11:30 |
2017-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270142
|
7.8 |
HIGH
Local
|
proxychains-ng_project
|
proxychains-ng
|
Untrusted search path vulnerability in ProxyChains-NG before 4.9 allows local users to gain privileges via a Trojan horse libproxychains4.so library in the current working directory, which is referen…
|
CWE-426
Untrusted Search Path
|
CVE-2015-3887
|
2024-11-21 11:30 |
2017-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270143
|
7.5 |
HIGH
Network
|
litespeedtech
|
openlitespeed
|
Use-after-free vulnerability in Open Litespeed before 1.3.10.
|
CWE-416
Use After Free
|
CVE-2015-3890
|
2024-11-21 11:30 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270144
|
8.1 |
HIGH
Network
|
helpdeskpro
|
helpdesk_pro
|
The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task.
|
CWE-74
Injection
|
CVE-2015-4075
|
2024-11-21 11:30 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270145
|
7.5 |
HIGH
Network
|
helpdesk_pro_project
|
helpdesk_pro
|
Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download…
|
CWE-22
Path Traversal
|
CVE-2015-4074
|
2024-11-21 11:30 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270146
|
9.8 |
CRITICAL
Network
|
helpdesk_pro_project
|
helpdesk_pro
|
Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (…
|
CWE-89
SQL Injection
|
CVE-2015-4073
|
2024-11-21 11:30 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270147
|
5.4 |
MEDIUM
Network
|
helpdesk_pro_project
|
helpdesk_pro
|
Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to name and m…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4072
|
2024-11-21 11:30 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270148
|
8.8 |
HIGH
Network
|
wpfastestcache
|
wp_fastest_cache
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin before 0.8.3.5 for WordPress allow remote attackers to hijack the…
|
CWE-352
Origin Validation Error
|
CVE-2015-4089
|
2024-11-21 11:30 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270149
|
6.1 |
MEDIUM
Network
|
phpbb
|
phpbb
|
Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and conduct phishing attacks via unspecifie…
|
CWE-601
Open Redirect
|
CVE-2015-3880
|
2024-11-21 11:30 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270150
|
7.5 |
HIGH
Network
|
etherpad
|
etherpad
|
Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.
|
CWE-22
Path Traversal
|
CVE-2015-4085
|
2024-11-21 11:30 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|