|
270861
|
- |
|
stageshow_project
|
stageshow
|
Open redirect vulnerability in the Redirect function in stageshow_redirect.php in the StageShow plugin before 5.0.9 for WordPress allows remote attackers to redirect users to arbitrary web sites and …
|
NVD-CWE-Other
|
CVE-2015-5461
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270862
|
- |
|
snorby_project
|
snorby
|
Cross-site scripting (XSS) vulnerability in app/views/events/_menu.html.erb in Snorby 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the title (cls.name variable) when creat…
|
CWE-79
Cross-site Scripting
|
CVE-2015-5460
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270863
|
- |
|
zohocorp
|
manageengine_password_manager_pro
|
SQL injection vulnerability in the AdvanceSearch.class in AdventNetPassTrix.jar in ManageEngine Password Manager Pro (PMP) before 8.1 Build 8101 allows remote authenticated users to execute arbitrary…
|
CWE-89
SQL Injection
|
CVE-2015-5459
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270864
|
- |
|
pivotx
|
pivotx
|
Session fixation vulnerability in fileupload.php in PivotX before 2.3.11 allows remote attackers to hijack web sessions via the sess parameter.
|
NVD-CWE-Other
|
CVE-2015-5458
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270865
|
- |
|
pivotx
|
pivotx
|
PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allows remote attackers to execute arbitrary code by uploading a crafted file, as de…
|
CWE-20
Improper Input Validation
|
CVE-2015-5457
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270866
|
- |
|
pivotx
|
pivotx
|
Cross-site scripting (XSS) vulnerability in the form method in modules/formclass.php in PivotX before 2.3.11 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, related …
|
CWE-79
Cross-site Scripting
|
CVE-2015-5456
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270867
|
- |
|
qualiteam
|
x-cart
|
Cross-site scripting (XSS) vulnerability in X-Cart 4.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to install/.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5455
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270868
|
- |
|
nucleuscms
|
nucleus_cms
|
Cross-site scripting (XSS) vulnerability in Nucleus CMS allows remote attackers to inject arbitrary web script or HTML via the title parameter when adding a new item.
|
CWE-79
Cross-site Scripting
|
CVE-2015-5454
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270869
|
- |
|
watchguard
|
xcs
|
Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.
|
CWE-77
Command Injection
|
CVE-2015-5453
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270870
|
- |
|
watchguard
|
xcs
|
SQL injection vulnerability in Watchguard XCS 9.2 and 10.0 before build 150522 allows remote attackers to execute arbitrary SQL commands via the sid cookie, as demonstrated by a request to borderpost…
|
CWE-89
SQL Injection
|
CVE-2015-5452
|
2024-11-21 11:33 |
2015-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|