|
272611
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via a custom JavaScri…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2938
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272612
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2, when using HHVM or Zend PHP, allows remote attackers to cause a denial of service ("quadratic blowup" and memory consumption) v…
|
CWE-399
Resource Management Errors
|
CVE-2015-2937
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272613
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki 1.24.x before 1.24.2, when using PBKDF2 for password hashing, allows remote attackers to cause a denial of service (CPU consumption) via a long password.
|
CWE-399
Resource Management Errors
|
CVE-2015-2936
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272614
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to bypass the SVG filtering and obtain sensitive user information via a mixed case @import in a style el…
|
CWE-200
Information Exposure
|
CVE-2015-2935
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272615
|
- |
|
mediawiki
|
mediawiki
|
MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 does not properly handle when the Zend interpreter xml_parse function does not expand entities, which allows remote attackers to…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2934
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272616
|
- |
|
mediawiki
|
mediawiki
|
Cross-site scripting (XSS) vulnerability in the Html class in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2933
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272617
|
- |
|
mediawiki
|
mediawiki
|
Incomplete blacklist vulnerability in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script or HTML via an animated href XLink …
|
CWE-79
Cross-site Scripting
|
CVE-2015-2932
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272618
|
- |
|
mediawiki
|
mediawiki
|
Incomplete blacklist vulnerability in includes/upload/UploadBase.php in MediaWiki before 1.19.24, 1.2x before 1.23.9, and 1.24.x before 1.24.2 allows remote attackers to inject arbitrary web script o…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2931
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272619
|
- |
|
bittorrent
|
sync
|
BitTorrent Sync allows remote attackers to execute arbitrary commands via a crafted btsync: link.
|
CWE-77
Command Injection
|
CVE-2015-2846
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272620
|
- |
|
redhat canonical debian gnu
|
enterprise_linux ubuntu_linux debian_linux mailman
|
Directory traversal vulnerability in GNU Mailman before 2.1.20, when not using a static alias, allows remote attackers to execute arbitrary files via a .. (dot dot) in a list name.
|
CWE-22
Path Traversal
|
CVE-2015-2775
|
2024-11-21 11:28 |
2015-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|