|
272461
|
- |
|
wpsymposium
|
wp_symposium
|
SQL injection vulnerability in forum.php in the WP Symposium plugin before 15.4 for WordPress allows remote attackers to execute arbitrary SQL commands via the show parameter in the QUERY_STRING to t…
|
CWE-89
SQL Injection
|
CVE-2015-3325
|
2024-11-21 11:29 |
2015-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272462
|
- |
|
quassel-irc debian
|
quassel debian_linux
|
Quassel before 0.12.2 does not properly re-initialize the database session when the PostgreSQL database is restarted, which allows remote attackers to conduct SQL injection attacks via a \ (backslash…
|
CWE-89
SQL Injection
|
CVE-2015-3427
|
2024-11-21 11:29 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272463
|
- |
|
thecartpress
|
thecartpress_ecommerce_shopping_cart
|
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to rea…
|
CWE-22
Path Traversal
|
CVE-2015-3301
|
2024-11-21 11:29 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272464
|
- |
|
thecartpress
|
thecartpress_ecommerce_shopping_cart
|
Multiple cross-site scripting (XSS) vulnerabilities in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allow remote atta…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3300
|
2024-11-21 11:29 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272465
|
- |
|
stunnel
|
stunnel
|
Stunnel 5.00 through 5.13, when using the redirect option, does not redirect client connections to the expected server after the initial connection, which allows remote attackers to bypass authentica…
|
CWE-284
Improper Access Control
|
CVE-2015-3644
|
2024-11-21 11:29 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272466
|
- |
|
yiiframework
|
yiiframework
|
Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.4 allows remote attackers to inject arbitrary web script or HTML via vectors related to JSON, arrays, and Internet Explorer 6 or 7.
|
CWE-79
Cross-site Scripting
|
CVE-2015-3397
|
2024-11-21 11:29 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272467
|
- |
|
trend_micro
|
scanmail
|
Trend Micro ScanMail for Microsoft Exchange (SMEX) 10.2 before Hot Fix Build 3318 and 11.0 before Hot Fix Build 4180 creates session IDs for the web console using a random number generator with predi…
|
NVD-CWE-Other
|
CVE-2015-3326
|
2024-11-21 11:29 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272468
|
- |
|
qemu redhat xen
|
qemu openstack enterprise_linux enterprise_virtualization xen
|
The Floppy Disk Controller (FDC) in QEMU, as used in Xen 4.5.x and earlier and KVM, allows local guest users to cause a denial of service (out-of-bounds write and guest crash) or possibly execute arb…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3456
|
2024-11-21 11:29 |
2015-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272469
|
- |
|
openstack oracle
|
keystone solaris
|
OpenStack Identity (Keystone) before 2014.1.5 and 2014.2.x before 2014.2.4 logs the backend_argument configuration option content, which allows remote authenticated users to obtain passwords and othe…
|
CWE-200
Information Exposure
|
CVE-2015-3646
|
2024-11-21 11:29 |
2015-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272470
|
- |
|
opensuse fedoraproject gnu
|
opensuse fedora libtasn1
|
The _asn1_extract_der_octet function in lib/decoding.c in GNU Libtasn1 before 4.5 allows remote attackers to cause a denial of service (out-of-bounds heap read) via a crafted certificate.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-3622
|
2024-11-21 11:29 |
2015-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|