|
272051
|
- |
|
cisco
|
email_security_appliance
|
The anti-spam scanner on Cisco Email Security Appliance (ESA) devices 3.3.1-09, 7.5.1-gpl-022, and 8.5.6-074 allows remote attackers to bypass intended e-mail restrictions via a malformed DNS SPF rec…
|
CWE-20
Improper Input Validation
|
CVE-2015-4184
|
2024-11-21 11:30 |
2015-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272052
|
- |
|
cisco
|
identity_services_engine_software
|
The administrative web interface in Cisco Identity Services Engine (ISE) before 1.3 allows remote authenticated users to bypass intended access restrictions, and obtain sensitive information or chang…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-4182
|
2024-11-21 11:30 |
2015-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272053
|
- |
|
strongswan debian canonical
|
strongswan_vpn_client debian_linux ubuntu_linux strongswan
|
strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication rest…
|
CWE-200
Information Exposure
|
CVE-2015-4171
|
2024-11-21 11:30 |
2015-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272054
|
- |
|
zanematthew
|
zm_ajax_login_\&_register
|
Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arbitrary php files via a relative path in the templ…
|
CWE-22
Path Traversal
|
CVE-2015-4153
|
2024-11-21 11:30 |
2015-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272055
|
- |
|
wftpserver
|
wing_ftp_server
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Wing FTP Server before 4.4.7 allow remote attackers to hijack the authentication of administrators for requests that (1) execute arbitrar…
|
CWE-352
Origin Validation Error
|
CVE-2015-4108
|
2024-11-21 11:30 |
2015-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272056
|
- |
|
coppermine-gallery
|
coppermine_photo_gallery
|
Coppermine Photo Gallery before 1.5.36 allows remote attackers to enumerate directories via a full path in the folder parameter to minibrowser.php.
|
CWE-200
Information Exposure
|
CVE-2015-3923
|
2024-11-21 11:30 |
2015-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272057
|
- |
|
dolibarr
|
dolibarr
|
Multiple cross-site scripting (XSS) vulnerabilities in Dolibarr ERP/CRM 3.5 and 3.6 allow remote attackers to inject arbitrary web script or HTML via the Business Search (search_nom) field to (1) htd…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3935
|
2024-11-21 11:30 |
2015-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272058
|
- |
|
apple redhat php
|
mac_os_x enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_node_eus php
|
The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property is a string, which allows remote attackers to obta…
|
CWE-20
Improper Input Validation
|
CVE-2015-4148
|
2024-11-21 11:30 |
2015-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272059
|
- |
|
redhat apple php
|
enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_linux_hpc_node_eus mac_os_x php
|
The SoapClient::__call method in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that __default_headers is an array, which allows remote attackers to…
|
CWE-19
Data Processing Errors
|
CVE-2015-4147
|
2024-11-21 11:30 |
2015-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272060
|
- |
|
redhat php apple
|
enterprise_linux php mac_os_x enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_hpc_node enterprise_linux_server_eus enterprise_li…
|
The pcntl_exec implementation in PHP before 5.4.41, 5.5.x before 5.5.25, and 5.6.x before 5.6.9 truncates a pathname upon encountering a \x00 character, which might allow remote attackers to bypass i…
|
CWE-19
Data Processing Errors
|
CVE-2015-4026
|
2024-11-21 11:30 |
2015-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|