|
271161
|
- |
|
avigilon
|
avigilon_control_center
|
Directory traversal vulnerability in Avigilon Control Center (ACC) 4 before 4.12.0.54 and 5 before 5.4.2.22 allows remote attackers to read arbitrary files via a crafted help/ URL.
|
CWE-22
Path Traversal
|
CVE-2015-2860
|
2024-11-21 11:28 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271162
|
- |
|
haxx hp oracle
|
curl libcurl system_management_homepage enterprise_manager_ops_center glassfish_server
|
The smb_request_state function in cURL and libcurl 7.40.0 through 7.42.1 allows remote SMB servers to obtain sensitive information from memory or cause a denial of service (out-of-bounds read and cra…
|
CWE-20
Improper Input Validation
|
CVE-2015-3237
|
2024-11-21 11:28 |
2015-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271163
|
- |
|
haxx
|
curl libcurl
|
cURL and libcurl 7.40.0 through 7.42.1 send the HTTP Basic authentication credentials for a previous connection when reusing a reset (curl_easy_reset) connection handle to send a request to the same …
|
CWE-200
Information Exposure
|
CVE-2015-3236
|
2024-11-21 11:28 |
2015-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271164
|
- |
|
drupal debian
|
drupal debian_linux
|
The OpenID module in Drupal 6.x before 6.36 and 7.x before 7.38 allows remote attackers to log into other users' accounts by leveraging an OpenID identity from certain providers, as demonstrated by t…
|
CWE-20
Improper Input Validation
|
CVE-2015-3234
|
2024-11-21 11:28 |
2015-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271165
|
- |
|
drupal
|
drupal
|
Open redirect vulnerability in the Overlay module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
|
NVD-CWE-Other
|
CVE-2015-3233
|
2024-11-21 11:28 |
2015-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271166
|
- |
|
drupal debian
|
drupal debian_linux
|
Open redirect vulnerability in the Field UI module in Drupal 7.x before 7.38 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the destination…
|
NVD-CWE-Other
|
CVE-2015-3232
|
2024-11-21 11:28 |
2015-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271167
|
- |
|
drupal debian
|
drupal debian_linux
|
The Render cache system in Drupal 7.x before 7.38, when used to cache content by user role, allows remote authenticated users to obtain private content viewed by user 1 by reading the cache.
|
CWE-200
Information Exposure
|
CVE-2015-3231
|
2024-11-21 11:28 |
2015-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271168
|
- |
|
airties
|
air_firmware
|
Stack-based buffer overflow in AirTies Air 6372, 5760, 5750, 5650TT, 5453, 5444TT, 5443, 5442, 5343, 5342, 5341, and 5021 DSL modems with firmware 1.0.2.0 and earlier allows remote attackers to execu…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2797
|
2024-11-21 11:28 |
2015-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271169
|
- |
|
vestacp
|
vesta_control_panel
|
Cross-site request forgery (CSRF) vulnerability in Vesta Control Panel before 0.9.8-14 allows remote attackers to hijack the authentication of arbitrary users.
|
CWE-352
Origin Validation Error
|
CVE-2015-2861
|
2024-11-21 11:28 |
2015-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271170
|
- |
|
akronymmanager_project
|
akronymmanager
|
SQL injection vulnerability in mod1/index.php in the Akronymmanager (sb_akronymmanager) extension before 7.0.0 for TYPO3 allows remote authenticated users with permission to maintain acronyms to exec…
|
CWE-89
SQL Injection
|
CVE-2015-2803
|
2024-11-21 11:28 |
2015-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|