|
272591
|
- |
|
fork-cms
|
fork_cms
|
Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) language[] or (2) type[] parameter to pr…
|
CWE-89
SQL Injection
|
CVE-2015-1467
|
2024-11-21 11:25 |
2015-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272592
|
- |
|
fli4l
|
fli4l
|
Multiple cross-site scripting (XSS) vulnerabilities in the web administration frontend in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allow remote attackers to inject arbitrary…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1444
|
2024-11-21 11:25 |
2015-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272593
|
- |
|
aas9
|
zerocms
|
SQL injection vulnerability in views/zero_transact_user.php in the administrative backend in ZeroCMS 1.3.3, 1.3.2, and earlier allows remote authenticated users to execute arbitrary SQL commands via …
|
CWE-89
SQL Injection
|
CVE-2015-1442
|
2024-11-21 11:25 |
2015-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272594
|
- |
|
mcafee
|
data_loss_prevention_endpoint
|
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1305
|
2024-11-21 11:25 |
2015-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272595
|
- |
|
ansible
|
tower
|
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connection to socket.io/1/.
|
CWE-200
Information Exposure
|
CVE-2015-1482
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272596
|
- |
|
ansible
|
tower
|
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1481
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272597
|
- |
|
manageengine
|
servicedesk_plus
|
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a dire…
|
CWE-200
Information Exposure
|
CVE-2015-1480
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272598
|
- |
|
zohocorp
|
servicedesk_plus
|
SQL injection vulnerability in reports/CreateReportTable.jsp in ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to execute arbitrary SQL commands via …
|
CWE-89
SQL Injection
|
CVE-2015-1479
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272599
|
- |
|
cmsjunkie
|
j-classifiedsmanager
|
Cross-site scripting (XSS) vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to inject arbitrary web script or HTML via the view parameter to /classifi…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1478
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272600
|
- |
|
cmsjunkie
|
j-classifiedsmanager
|
SQL injection vulnerability in the CMSJunkie J-ClassifiedsManager component for Joomla! allows remote attackers to execute arbitrary SQL commands via the id parameter in a viewad task to classifieds/…
|
CWE-89
SQL Injection
|
CVE-2015-1477
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|