|
270991
|
- |
|
sap
|
netweaver
|
The (1) Cross-System Tools and (2) Data Transfer Workbench in SAP NetWeaver have hardcoded credentials, which allows remote attackers to obtain access via unspecified vectors, aka SAP Security Notes …
|
CWE-255
Credentials Management
|
CVE-2015-5067
|
2024-11-21 11:32 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270992
|
- |
|
metalgenix
|
genixcms
|
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) content or (2) title field in an add act…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5066
|
2024-11-21 11:32 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270993
|
- |
|
intelligent-it
|
paypal_currency_converter_basic_for_woocommerce
|
Absolute path traversal vulnerability in proxy.php in the google currency lookup in the Paypal Currency Converter Basic For WooCommerce plugin before 1.4 for WordPress allows remote attackers to read…
|
CWE-22
Path Traversal
|
CVE-2015-5065
|
2024-11-21 11:32 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270994
|
- |
|
mysql-lite-administrator_project
|
mysql-lite-administrator
|
Multiple cross-site scripting (XSS) vulnerabilities in MySql Lite Administrator (mysql-lite-administrator) beta-1 allow remote attackers to inject arbitrary web script or HTML via the table_name para…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5064
|
2024-11-21 11:32 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270995
|
- |
|
silverstripe
|
silverstripe
|
Multiple cross-site scripting (XSS) vulnerabilities in SilverStripe CMS & Framework 3.1.13 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_username or (2) admin_passwo…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5063
|
2024-11-21 11:32 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270996
|
- |
|
silverstripe
|
silverstripe
|
Open redirect vulnerability in SilverStripe CMS & Framework 3.1.13 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the returnURL parameter t…
|
NVD-CWE-Other
|
CVE-2015-5062
|
2024-11-21 11:32 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270997
|
- |
|
zohocorp
|
manageengine_assetexplorer
|
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine AssetExplorer 6.1 service pack 6112 and earlier allows remote authenticated users with permissions to add new vendors to inject arbitrary…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5061
|
2024-11-21 11:32 |
2015-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270998
|
9.8 |
CRITICAL
Network
|
pexip
|
pexip_infinity
|
The client API authentication mechanism in Pexip Infinity before 10 allows remote attackers to gain privileges via a crafted request.
|
CWE-269
Improper Privilege Management
|
CVE-2015-4719
|
2024-11-21 11:31 |
2020-09-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270999
|
7.5 |
HIGH
Network
|
mongodb fedoraproject
|
bson fedora
|
The Moped::BSON::ObjecId.legal? method in mongodb/bson-ruby before 3.0.4 as used in rubygem-moped allows remote attackers to cause a denial of service (worker resource consumption) via a crafted stri…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-4411
|
2024-11-21 11:31 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271000
|
7.5 |
HIGH
Network
|
moped_project fedoraproject
|
moped fedora
|
The Moped::BSON::ObjecId.legal? method in rubygem-moped before commit dd5a7c14b5d2e466f7875d079af71ad19774609b allows remote attackers to cause a denial of service (worker resource consumption) or pe…
|
CWE-20
Improper Input Validation
|
CVE-2015-4410
|
2024-11-21 11:31 |
2020-02-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|