|
272831
|
- |
|
moodle
|
moodle
|
Cross-site scripting (XSS) vulnerability in the external_format_text function in lib/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows re…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3178
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272832
|
- |
|
moodle
|
moodle
|
Moodle 2.8.x before 2.8.6 does not consider the tool/monitor:subscribe capability before entering subscriptions to site-wide event-monitor rules, which allows remote authenticated users to obtain sen…
|
CWE-17
Code
|
CVE-2015-3177
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272833
|
- |
|
moodle
|
moodle
|
The account-confirmation feature in login/confirm.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allows remote attackers to obtain sensitive full-name in…
|
CWE-200
Information Exposure
|
CVE-2015-3176
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272834
|
- |
|
moodle
|
moodle
|
Multiple open redirect vulnerabilities in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 allow remote attackers to redirect users to arbitrary web sites and con…
|
NVD-CWE-Other
|
CVE-2015-3175
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272835
|
- |
|
moodle
|
moodle
|
mod/quiz/db/access.php in Moodle through 2.5.9, 2.6.x before 2.6.11, 2.7.x before 2.7.8, and 2.8.x before 2.8.6 does not set the RISK_XSS bit for graders, which allows remote authenticated users to c…
|
CWE-79
Cross-site Scripting
|
CVE-2015-3174
|
2024-11-21 11:28 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272836
|
- |
|
zenphoto
|
zenphoto
|
Cross-site scripting (XSS) vulnerability in ZenPhoto20 1.1.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2949
|
2024-11-21 11:28 |
2015-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272837
|
- |
|
zenphoto
|
zenphoto
|
Cross-site scripting (XSS) vulnerability in the image processor in Zenphoto before 1.4.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2948
|
2024-11-21 11:28 |
2015-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272838
|
- |
|
blue_coat
|
ssl_visibility_appliance_sv800_firmware ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv3800_firmware ssl_visibility_appliance_sv2800_firmware
|
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not set the secure flag for the administrator's cookie in an https se…
|
CWE-200
Information Exposure
|
CVE-2015-2855
|
2024-11-21 11:28 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272839
|
- |
|
blue_coat
|
ssl_visibility_appliance_sv800_firmware ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv2800_firmware ssl_visibility_appliance_sv3800_firmware
|
The WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 does not send a restrictive X-Frame-Options HTTP header, which allows remo…
|
CWE-20
Improper Input Validation
|
CVE-2015-2854
|
2024-11-21 11:28 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272840
|
- |
|
blue_coat
|
ssl_visibility_appliance_sv3800_firmware ssl_visibility_appliance_sv2800_firmware ssl_visibility_appliance_sv1800_firmware ssl_visibility_appliance_sv800_firmware
|
Session fixation vulnerability in the WebUI component in Blue Coat SSL Visibility Appliance SV800, SV1800, SV2800, and SV3800 3.6.x through 3.8.x before 3.8.4 allows remote attackers to hijack web se…
|
NVD-CWE-Other
|
CVE-2015-2853
|
2024-11-21 11:28 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|