|
298621
|
- |
|
bluecoat
|
sgos proxysg proxysg_sg210-10 proxysg_sg210-25 proxysg_sg210-5 proxysg_sg510-10 proxysg_sg510-20 proxysg_sg510-25 proxysg_sg510-5 proxysg_sg810-10 proxysg_sg810-20 pr…
|
Cross-site scripting (XSS) vulnerability in the Java Management Console in Blue Coat ProxySG before SGOS 4.3.4.1, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.1.1 allows …
|
CWE-79
Cross-site Scripting
|
CVE-2010-5192
|
2024-11-21 10:22 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298622
|
- |
|
bluecoat
|
avos proxyav
|
Multiple cross-site request forgery (CSRF) vulnerabilities on the Blue Coat ProxyAV appliance before 3.2.6.1 allow remote attackers to hijack the authentication of administrators for requests that (1…
|
CWE-352
Origin Validation Error
|
CVE-2010-5191
|
2024-11-21 10:22 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298623
|
- |
|
bluecoat
|
sgos proxysg proxysg_sg210-10 proxysg_sg210-25 proxysg_sg210-5 proxysg_sg510-10 proxysg_sg510-20 proxysg_sg510-25 proxysg_sg510-5 proxysg_sg810-10 proxysg_sg810-20 pr…
|
The Active Content Transformation functionality in Blue Coat ProxySG before SGOS 4.3.4.2, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.2.1 allows remote attackers to bypa…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-5190
|
2024-11-21 10:22 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298624
|
- |
|
bluecoat
|
sgos proxysg proxysg_sg210-10 proxysg_sg210-25 proxysg_sg210-5 proxysg_sg510-10 proxysg_sg510-20 proxysg_sg510-25 proxysg_sg510-5 proxysg_sg810-10 proxysg_sg810-20 pr…
|
Blue Coat ProxySG before SGOS 4.3.4.1, 5.x before SGOS 5.4.5.1, 5.5 before SGOS 5.5.4.1, and 6.x before SGOS 6.1.1.1 allows remote authenticated users to execute arbitrary CLI commands by leveraging …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-5189
|
2024-11-21 10:22 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298625
|
- |
|
silverstripe
|
silverstripe
|
SilverStripe 2.3.x before 2.3.6 allows remote attackers to obtain sensitive information via the (1) debug_memory parameter to core/control/Director.php or (2) debug_profile parameter to main.php.
|
CWE-200
Information Exposure
|
CVE-2010-5188
|
2024-11-21 10:22 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298626
|
- |
|
silverstripe
|
silverstripe
|
SilverStripe 2.3.x before 2.3.8 and 2.4.x before 2.4.1, when running on servers with certain configurations, allows remote attackers to obtain sensitive information via a direct request to PHP files …
|
CWE-200
Information Exposure
|
CVE-2010-5187
|
2024-11-21 10:22 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298627
|
- |
|
silverstripe
|
silverstripe
|
Cross-site scripting (XSS) vulnerability in SilverStripe 2.3.x before 2.3.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to DataObjectSet pagination.
|
CWE-79
Cross-site Scripting
|
CVE-2010-5095
|
2024-11-21 10:22 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298628
|
- |
|
silverstripe
|
silverstripe
|
The deleteinstallfiles function in control/ContentController.php in SilverStripe 2.3.x before 2.3.7 does not require ADMIN permissions, which allows remote attackers to delete index.php and "disrupt …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-5094
|
2024-11-21 10:22 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298629
|
- |
|
silverstripe
|
silverstripe
|
Member_ProfileForm in security/Member.php in SilverStripe 2.3.x before 2.3.7 allows remote attackers to hijack user accounts by saving data using the email address (ID) of another user.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2010-5093
|
2024-11-21 10:22 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298630
|
- |
|
silverstripe
|
silverstripe
|
The Add Member dialog in the Security admin page in SilverStripe 2.4.0 saves user passwords in plaintext, which allows local users to obtain sensitive information by reading a database.
|
CWE-255
Credentials Management
|
CVE-2010-5092
|
2024-11-21 10:22 |
2012-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|