|
271341
|
- |
|
broadcom
|
spectrum
|
Cross-site scripting (XSS) vulnerability in CA Spectrum 9.2.x and 9.3.x before 9.3 H02 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2827
|
2024-11-21 11:28 |
2015-04-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271342
|
- |
|
simple_ads_manager_project
|
simple_ads_manager
|
Multiple SQL injection vulnerabilities in the Simple Ads Manager plugin before 2.7.97 for WordPress allow remote attackers to execute arbitrary SQL commands via a (1) hits[][] parameter in a sam_hits…
|
CWE-89
SQL Injection
|
CVE-2015-2824
|
2024-11-21 11:28 |
2015-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271343
|
- |
|
citrix
|
netscaler
|
Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restrictions via a crafted Content-Type header, as demonstrated by the application/octet-s…
|
CWE-284
Improper Access Control
|
CVE-2015-2841
|
2024-11-21 11:28 |
2015-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271344
|
- |
|
citrix
|
netscaler
|
Cross-site scripting (XSS) vulnerability in help/rt/large_search.html in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to inject arbitrary web script or HTML via the searchQuery p…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2840
|
2024-11-21 11:28 |
2015-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271345
|
- |
|
citrix
|
netscaler
|
The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error message, which allows remote attackers to conduct cross-site scripting (XSS) attacks …
|
CWE-79
Cross-site Scripting
|
CVE-2015-2839
|
2024-11-21 11:28 |
2015-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271346
|
- |
|
citrix
|
netscaler
|
Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote attackers to hijack the authentication of administrators for requests that exec…
|
CWE-352
Origin Validation Error
|
CVE-2015-2838
|
2024-11-21 11:28 |
2015-04-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271347
|
- |
|
typo3
|
neos
|
TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes in the workspace of other editors via unspecified vectors.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-2821
|
2024-11-21 11:28 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271348
|
- |
|
sap
|
afaria
|
Buffer overflow in XcListener in SAP Afaria 7.0.6001.5 allows remote attackers to cause a denial of service (process termination) via a crafted request, aka SAP Security Note 2132584.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2820
|
2024-11-21 11:28 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271349
|
- |
|
sap
|
sql_anywhere
|
SAP Sybase SQL Anywhere 11 and 16 allows remote attackers to cause a denial of service (crash) via a crafted request, aka SAP Security Note 2108161.
|
CWE-20
Improper Input Validation
|
CVE-2015-2819
|
2024-11-21 11:28 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271350
|
- |
|
sap
|
mobile_platform
|
XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125513.
|
NVD-CWE-Other
|
CVE-2015-2818
|
2024-11-21 11:28 |
2015-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|