|
271761
|
8.8 |
HIGH
Network
|
wpfastestcache
|
wp_fastest_cache
|
Multiple cross-site request forgery (CSRF) vulnerabilities in the optionsPageRequest function in admin.php in WP Fastest Cache plugin before 0.8.3.5 for WordPress allow remote attackers to hijack the…
|
CWE-352
Origin Validation Error
|
CVE-2015-4089
|
2024-11-21 11:30 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271762
|
6.1 |
MEDIUM
Network
|
phpbb
|
phpbb
|
Open redirect vulnerability in phpBB before 3.0.14 and 3.1.x before 3.1.4 allows remote attackers to redirect users of Google Chrome to arbitrary web sites and conduct phishing attacks via unspecifie…
|
CWE-601
Open Redirect
|
CVE-2015-3880
|
2024-11-21 11:30 |
2017-09-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271763
|
7.5 |
HIGH
Network
|
etherpad
|
etherpad
|
Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.
|
CWE-22
Path Traversal
|
CVE-2015-4085
|
2024-11-21 11:30 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271764
|
9.8 |
CRITICAL
Network
|
strongswan
|
strongswan
|
strongSwan 5.2.2 and 5.3.0 allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code.
|
CWE-19
Data Processing Errors
|
CVE-2015-3991
|
2024-11-21 11:30 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271765
|
5.4 |
MEDIUM
Network
|
ge
|
multilink_ml810_firmware multilink_ml3000_firmware multilink_ml3100_firmware multilink_ml800_firmware multilink_ml1200_firmware multilink_ml1600_firmware multilink_ml2400_firmware
|
Cross-site scripting (XSS) vulnerability in GE Multilink ML810/3000/3100 series switch 5.2.0 and earlier, and GE Multilink ML800/1200/1600/2400 4.2.1 and earlier.
|
CWE-79
Cross-site Scripting
|
CVE-2015-3976
|
2024-11-21 11:30 |
2017-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271766
|
7.5 |
HIGH
Network
|
phpmybackuppro
|
phpmybackuppro
|
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of …
|
CWE-22
Path Traversal
|
CVE-2015-4181
|
2024-11-21 11:30 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271767
|
7.5 |
HIGH
Network
|
phpmybackuppro
|
phpmybackuppro
|
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.4 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of …
|
CWE-22
Path Traversal
|
CVE-2015-4180
|
2024-11-21 11:30 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271768
|
7.5 |
HIGH
Network
|
saltstack
|
salt
|
Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
|
CWE-295
Improper Certificate Validation
|
CVE-2015-4017
|
2024-11-21 11:30 |
2017-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271769
|
5.3 |
MEDIUM
Network
|
helpdesk_pro_project
|
helpdesk_pro
|
The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/…
|
CWE-200
Information Exposure
|
CVE-2015-4071
|
2024-11-21 11:30 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271770
|
6.5 |
MEDIUM
Network
|
attic_project
|
attic
|
attic before 0.15 does not confirm unencrypted backups with the user, which allows remote attackers with read and write privileges for the encrypted repository to obtain potentially sensitive informa…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-4082
|
2024-11-21 11:30 |
2017-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|