|
272831
|
9.8 |
CRITICAL
Network
|
fast-image-adder_project
|
fast-image-adder
|
Remote file upload vulnerability in fast-image-adder v1.1 Wordpress plugin
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-1000001
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272832
|
9.8 |
CRITICAL
Network
|
mailcwp_project
|
mailcwp
|
Remote file upload vulnerability in mailcwp v1.99 wordpress plugin
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-1000000
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272833
|
- |
|
ininet_solutions
|
scada_web_server
|
IniNet embeddedWebServer (aka eWebServer) before 2.02 for Windows CE uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information via unspecified vect…
|
CWE-200
Information Exposure
|
CVE-2015-1005
|
2024-11-21 11:24 |
2015-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272834
|
- |
|
ininet_solutions
|
scada_web_server
|
Directory traversal vulnerability in IniNet embeddedWebServer (aka eWebServer) before 2.02 allows remote attackers to read arbitrary files via a crafted pathname.
|
CWE-22
Path Traversal
|
CVE-2015-1003
|
2024-11-21 11:24 |
2015-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272835
|
- |
|
ininet_solutions
|
scada_web_server
|
IniNet embeddedWebServer (aka eWebServer) before 2.02 mishandles URL encoding, which allows remote attackers to write to or delete files via a crafted string.
|
NVD-CWE-Other
|
CVE-2015-1002
|
2024-11-21 11:24 |
2015-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272836
|
- |
|
ininet_solutions
|
scada_web_server
|
Multiple stack-based buffer overflows in IniNet embeddedWebServer (aka eWebServer) before 2.02 allow remote attackers to execute arbitrary code via a long field in an HTTP request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-1001
|
2024-11-21 11:24 |
2015-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272837
|
- |
|
vmware
|
vcenter_server
|
vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.
|
CWE-20
Improper Input Validation
|
CVE-2015-1047
|
2024-11-21 11:24 |
2015-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272838
|
- |
|
omron
|
cx-programmer cj2m_plc cj2h_plc
|
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 use a reversible format for password storage in object files on Compact Flash cards, which makes it…
|
CWE-200
Information Exposure
|
CVE-2015-1015
|
2024-11-21 11:24 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272839
|
- |
|
omron
|
cx-programmer
|
Omron CX-One CX-Programmer before 9.6 uses a reversible format for password storage in project source-code files, which makes it easier for local users to obtain sensitive information by reading a fi…
|
CWE-200
Information Exposure
|
CVE-2015-0988
|
2024-11-21 11:24 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272840
|
- |
|
omron
|
cx-programmer cj2h_plc cj2m_plc
|
Omron CX-One CX-Programmer before 9.6, CJ2M PLC devices before 2.1, and CJ2H PLC devices before 1.5 rely on cleartext password transmission, which allows remote attackers to obtain sensitive informat…
|
CWE-200
Information Exposure
|
CVE-2015-0987
|
2024-11-21 11:24 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|