|
270841
|
- |
|
ibm
|
maximo_asset_management maximo_for_nuclear_power maximo_for_utilities maximo_for_life_sciences maximo_for_oil_and_gas maximo_for_transportation maximo_for_government smartcloud_c…
|
SQL injection vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x before 7.5.0.8 IFIX004 a…
|
CWE-89
SQL Injection
|
CVE-2015-4967
|
2024-11-21 11:32 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270842
|
- |
|
ibm
|
maximo_asset_management maximo_for_nuclear_power maximo_for_utilities maximo_for_life_sciences maximo_for_oil_and_gas maximo_for_transportation maximo_for_government smartcloud_c…
|
maximouiweb/webmodule/webclient/utility/merlin.jsp in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX004, and 7.6.0 before 7.6.0.1 IFIX002; Maximo Asset Management 7.5.x b…
|
CWE-200
Information Exposure
|
CVE-2015-4965
|
2024-11-21 11:32 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270843
|
- |
|
ibm
|
urbancode_deploy
|
IBM UrbanCode Deploy 6.0 and 6.0.1.x before 6.0.1.10, 6.1.1.x before 6.1.1.8, and 6.1.2 writes admin AUTH_TOKEN values to execution logs, which allows remote authenticated users to gain privileges by…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-4964
|
2024-11-21 11:32 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270844
|
- |
|
ibm
|
maximo_asset_management maximo_for_nuclear_power maximo_for_utilities maximo_for_life_sciences maximo_for_oil_and_gas maximo_for_transportation maximo_for_government smartcloud_c…
|
Cross-site scripting (XSS) vulnerability in IBM Maximo Asset Management 7.1 through 7.1.1.13, 7.5.0 before 7.5.0.8 IFIX003, and 7.6.0 before 7.6.0.1 IFIX001; Maximo Asset Management 7.5.x before 7.5.…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4944
|
2024-11-21 11:32 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270845
|
- |
|
ibm
|
emptoris_program_management emptoris_supplier_lifecycle_management emptoris_strategic_supply_management
|
Cross-site scripting (XSS) vulnerability in IBM Emptoris Supplier Lifecycle Management and Emptoris Program Management 10.x before 10.0.1.4_iFix3, 10.0.2.x before 10.0.2.7_iFix1, 10.0.3.x before 10.0…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4939
|
2024-11-21 11:32 |
2015-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270846
|
- |
|
ibm
|
qradar_security_information_and_event_manager
|
IBM QRadar SIEM 7.1 MR2 before Patch 11 IF02 and 7.2.x before 7.2.5 Patch 4 allows remote authenticated users to execute arbitrary commands with root privileges by leveraging admin access.
|
CWE-77
Command Injection
|
CVE-2015-4930
|
2024-11-21 11:32 |
2015-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270847
|
- |
|
ibm
|
business_process_manager
|
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 8.0.x through 8.0.1.3, 8.5.0 through 8.5.0.1, 8.5.5 through 8.5.5.0, and 8.5.6 before 8.5.6.0 CF1 allows remote authenti…
|
CWE-79
Cross-site Scripting
|
CVE-2015-4955
|
2024-11-21 11:32 |
2015-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270848
|
- |
|
x2engine
|
x2crm
|
Cross-site request forgery (CSRF) vulnerability in X2Engine X2CRM before 5.2 allows remote attackers to hijack the authentication of administrators for requests that create an administrative account …
|
CWE-352
Origin Validation Error
|
CVE-2015-5075
|
2024-11-21 11:32 |
2015-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270849
|
- |
|
x2engine
|
x2crm
|
Incomplete blacklist vulnerability in the FileUploadsFilter class in protected/components/filters/FileUploadsFilter.php in X2Engine X2CRM before 5.0.9 allows remote authenticated users to execute arb…
|
CWE-20
Improper Input Validation
|
CVE-2015-5074
|
2024-11-21 11:32 |
2015-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270850
|
- |
|
x2engine
|
x2crm
|
Multiple cross-site scripting (XSS) vulnerabilities in X2Engine X2CRM before 5.0.9 allow remote attackers to inject arbitrary web script or HTML via the (1) version parameter in protected/views/admin…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5076
|
2024-11-21 11:32 |
2015-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|