|
269561
|
7.5 |
HIGH
Network
|
moodle
|
moodle
|
lib/moodlelib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 relies on the PHP mt_rand function to implement the random_string and complex_random_string…
|
CWE-200 CWE-254
Information Exposure 7PK - Security Features
|
CVE-2015-5267
|
2024-11-21 11:32 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269562
|
6.8 |
MEDIUM
Network
|
moodle
|
moodle
|
The enrol_meta_sync function in enrol/meta/locallib.php in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to obtain manager p…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5266
|
2024-11-21 11:32 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269563
|
4.3 |
MEDIUM
Network
|
moodle
|
moodle
|
The wiki component in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 does not consider the mod/wiki:managefiles capability before authorizing file management, …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5265
|
2024-11-21 11:32 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269564
|
5.4 |
MEDIUM
Network
|
moodle
|
moodle
|
The lesson module in Moodle through 2.6.11, 2.7.x before 2.7.10, 2.8.x before 2.8.8, and 2.9.x before 2.9.2 allows remote authenticated users to bypass intended access restrictions and enter addition…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-5264
|
2024-11-21 11:32 |
2016-02-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269565
|
8.8 |
HIGH
Network
|
ibm
|
emptoris_contract_management
|
Cross-site request forgery (CSRF) vulnerability in IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.…
|
CWE-352
Origin Validation Error
|
CVE-2015-5050
|
2024-11-21 11:32 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269566
|
7.5 |
HIGH
Network
|
ibm
|
emptoris_contract_management
|
IBM Emptoris Contract Management 9.5.0.x before 9.5.0.6 iFix15, 10.0.0.x and 10.0.1.x before 10.0.1.5 iFix5, 10.0.2.x before 10.0.2.7 iFix4, and 10.0.4.x before 10.0.4.0 iFix3 allows remote attackers…
|
CWE-20
Improper Input Validation
|
CVE-2015-5042
|
2024-11-21 11:32 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269567
|
7.5 |
HIGH
Network
|
ibm
|
security_access_manager_for_web_7.0_firmware security_access_manager_for_web_8.0_firmware security_access_manager_9.0_firmware
|
The SSH implementation on IBM Security Access Manager for Web appliances 7.0 before 7.0.0 FP19, 8.0 before 8.0.1.3 IF3, and 9.0 before 9.0.0.0 IF1 does not properly restrict the set of MAC algorithms…
|
CWE-310
Cryptographic Issues
|
CVE-2015-5012
|
2024-11-21 11:32 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269568
|
7.5 |
HIGH
Network
|
ibm
|
security_access_manager_for_web_8.0_firmware security_access_manager_for_web_7.0_firmware security_access_manager_9.0_firmware
|
IBM Security Access Manager for Web 7.0 before 7.0.0 IF21, 8.0 before 8.0.1.3 IF4, and 9.0 before 9.0.0.1 IF1 does not have a lockout mechanism for invalid login attempts, which makes it easier for r…
|
CWE-254
7PK - Security Features
|
CVE-2015-5010
|
2024-11-21 11:32 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269569
|
4.0 |
MEDIUM
Local
|
ibm
|
spss_modeler
|
IBM SPSS Modeler 14.2 through FP3 IF027, 15 through FP3 IF015, 16 through FP2 IF012, 17 through FP1 IF018, and 17.1 through IF008 includes unspecified cleartext data in memory dumps, which allows loc…
|
CWE-200
Information Exposure
|
CVE-2015-4991
|
2024-11-21 11:32 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269570
|
5.4 |
MEDIUM
Network
|
ibm
|
qradar_security_information_and_event_manager
|
Cross-site scripting (XSS) vulnerability in the Web UI in IBM Security QRadar SIEM 7.1.x before 7.1 MR2 Patch 12 allows remote authenticated users to inject arbitrary web script or HTML via a crafted…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4957
|
2024-11-21 11:32 |
2016-02-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|