|
272551
|
- |
|
hotspotexpress
|
hotex_billing_manager
|
Hotspot Express hotEx Billing Manager 73 does not include the HTTPOnly flag in a Set-Cookie header, which makes it easier for remote attackers to obtain potentially sensitive information via script a…
|
CWE-200
Information Exposure
|
CVE-2015-3319
|
2024-11-21 11:29 |
2015-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272552
|
- |
|
fortinet
|
fortimail
|
FortiMail 5.0.3 through 5.2.3 allows remote administrators to obtain credentials via the "diag debug application httpd" command.
|
CWE-200
Information Exposure
|
CVE-2015-3293
|
2024-11-21 11:29 |
2015-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272553
|
5.9 |
MEDIUM
Network
|
line
|
line\
|
LINE@ for Android version 1.0.0 and LINE@ for iOS version 1.0.0 are vulnerable to MITM (man-in-the-middle) attack since the application allows non-SSL/TLS communications. As a result, any API may be …
|
CWE-924
Improper Enforcement of Message Integrity During Transmission in a Communication Channel
|
CVE-2015-2968
|
2024-11-21 11:28 |
2023-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272554
|
5.3 |
MEDIUM
Network
|
openshift
|
origin
|
In Openshift Origin 3 the cookies being set in console have no 'secure', 'HttpOnly' attributes.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2015-3207
|
2024-11-21 11:28 |
2022-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272555
|
7.2 |
HIGH
Network
|
custom_content_type_manager_project
|
custom_content_type_manager
|
custom-content-type-manager Wordpress plugin can be used by an administrator to achieve arbitrary PHP remote code execution.
|
CWE-94
Code Injection
|
CVE-2015-3173
|
2024-11-21 11:28 |
2022-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272556
|
5.4 |
MEDIUM
Network
|
eidogo
|
eidogo
|
EidoGo is susceptible to Cross-Site Scripting (XSS) attacks via maliciously crafted SGF input.
|
CWE-79
Cross-site Scripting
|
CVE-2015-3172
|
2024-11-21 11:28 |
2022-07-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272557
|
6.5 |
MEDIUM
Network
|
juniper
|
junos
|
On the QFX3500 and QFX3600 platforms, the number of bytes collected from the RANDOM_INTERRUPT entropy source when the device boots up is insufficient, possibly leading to weak or duplicate SSH keys o…
|
CWE-331
Insufficient Entropy
|
CVE-2015-3006
|
2024-11-21 11:28 |
2020-02-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272558
|
6.1 |
MEDIUM
Network
|
apache
|
struts
|
Apache Struts before 2.3.20 has a cross-site scripting (XSS) vulnerability.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2992
|
2024-11-21 11:28 |
2020-02-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272559
|
6.5 |
MEDIUM
Adjacent
|
freebsd
|
freebsd
|
The Neighbor Discovery (ND) protocol implementation in the IPv6 stack in FreeBSD through 10.1 allows remote attackers to reconfigure a hop-limit setting via a small hop_limit value in a Router Advert…
|
CWE-20
Improper Input Validation
|
CVE-2015-2923
|
2024-11-21 11:28 |
2020-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272560
|
9.8 |
CRITICAL
Network
|
netvu
|
dv-ip_express_firmware sd-advanced_-_sdhd_firmware sd-advanced_8\/12\/16_vga_firmware sd_advanced_closed_iptv_\(m3u\)_firmware sd_advanced_non_closed_iptv_\(m3u\)_firmware sd_advanced_…
|
Dedicated Micros DV-IP Express, SD Advanced, SD, EcoSense, and DS2 devices rely on a GUI warning to help ensure that the administrator configures login credentials, which makes it easier for remote a…
|
CWE-269
Improper Privilege Management
|
CVE-2015-2909
|
2024-11-21 11:28 |
2020-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|