|
269211
|
7.5 |
HIGH
Network
|
plone
|
plone
|
Plone 3.3.0 through 3.3.6 allows remote attackers to inject headers into HTTP responses.
|
CWE-20
Improper Input Validation
|
CVE-2015-7318
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269212
|
6.8 |
MEDIUM
Network
|
kupu_project plone
|
kupu plone
|
Kupu 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, and 4.2.0 through 4.2.7 allows remote authenticated users to edit Kupu settings.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-7317
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269213
|
6.1 |
MEDIUM
Network
|
plone
|
plone
|
Cross-site scripting (XSS) vulnerability in Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.x before 4.3.7, and 5.0rc1.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7316
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269214
|
5.9 |
MEDIUM
Network
|
plone
|
plone
|
Plone 3.3.0 through 3.3.6, 4.0.0 through 4.0.10, 4.1.0 through 4.1.6, 4.2.0 through 4.2.7, 4.3.0 through 4.3.6, and 5.0rc1 allows remote attackers to add a new member to a Plone site with registratio…
|
CWE-284
Improper Access Control
|
CVE-2015-7315
|
2024-11-21 11:36 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269215
|
4.8 |
MEDIUM
Network
|
zcms_project
|
zcms
|
Cross-site scripting (XSS) vulnerability in ZCMS JavaServer Pages Content Management System 1.1.
|
CWE-79
Cross-site Scripting
|
CVE-2015-7347
|
2024-11-21 11:36 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269216
|
4.7 |
MEDIUM
Local
|
redhat
|
enterprise_linux kernel-rt enterprise_mrg
|
Race condition in the kernel in Red Hat Enterprise Linux 7, kernel-rt and Red Hat Enterprise MRG 2, when the nfnetlink_log module is loaded, allows local users to cause a denial of service (panic) by…
|
CWE-362
Race Condition
|
CVE-2015-7553
|
2024-11-21 11:36 |
2017-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269217
|
7.5 |
HIGH
Network
|
ldapauth-fork_project
|
ldapauth-fork
|
ldapauth-fork before 2.3.3 allows remote attackers to perform LDAP injection attacks via a crafted username.
|
CWE-90
LDAP Injection
|
CVE-2015-7294
|
2024-11-21 11:36 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269218
|
9.8 |
CRITICAL
Network
|
sap
|
netweaver
|
XML External Entity (XXE) vulnerability in SAP Netweaver before 7.01.
|
CWE-611
XXE
|
CVE-2015-7241
|
2024-11-21 11:36 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269219
|
5.3 |
MEDIUM
Network
|
tinfoilsecurity
|
devise-two-factor
|
Tinfoil Devise-two-factor before 2.0.0 does not strictly follow section 5.2 of RFC 6238 and does not "burn" a successfully validated one-time password (aka OTP), which allows remote or physically pro…
|
CWE-254
7PK - Security Features
|
CVE-2015-7225
|
2024-11-21 11:36 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269220
|
9.8 |
CRITICAL
Network
|
labwebdesigns
|
double_opt-in_for_download
|
Multiple SQL injection vulnerabilities in the Double Opt-In for Download plugin before 2.0.9 for WordPress allow remote attackers to execute arbitrary SQL commands via the ver parameter to (1) class-…
|
CWE-89
SQL Injection
|
CVE-2015-7517
|
2024-11-21 11:36 |
2017-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|