|
273421
|
- |
|
mikrotik
|
routeros
|
Cross-site request forgery (CSRF) vulnerability in MikroTik RouterOS 5.0 and earlier allows remote attackers to hijack the authentication of administrators for requests that change the administrator …
|
CWE-352
Origin Validation Error
|
CVE-2015-2350
|
2024-11-21 11:27 |
2015-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273422
|
- |
|
superwebmailer
|
superwebmailer
|
Cross-site scripting (XSS) vulnerability in defaultnewsletter.php in SuperWebMailer 5.60.0.01190 and earlier allows remote attackers to inject arbitrary web script or HTML via the HTMLForm parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2349
|
2024-11-21 11:27 |
2015-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273423
|
- |
|
fortinet
|
single_sign_on
|
Stack-based buffer overflow in collectoragent.exe in Fortinet Single Sign On (FSSO) before build 164 allows remote attackers to execute arbitrary code via a large PROCESS_HELLO message to the Message…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-2281
|
2024-11-21 11:27 |
2015-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273424
|
- |
|
mageia_project python canonical
|
mageia requests ubuntu_linux
|
The resolve_redirects function in sessions.py in requests 2.1.0 through 2.5.3 allows remote attackers to conduct session fixation attacks via a cookie without a host value in a redirect.
|
NVD-CWE-Other
|
CVE-2015-2296
|
2024-11-21 11:27 |
2015-03-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273425
|
- |
|
mybb
|
mybb
|
A JSON library in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to obtain the installation path via unknown vectors.
|
CWE-200
Information Exposure
|
CVE-2015-2335
|
2024-11-21 11:27 |
2015-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273426
|
- |
|
mybb
|
mybb
|
Cross-site request forgery (CSRF) vulnerability in the Admin Control Panel (ACP) login in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to hijack the authentication of unspecified v…
|
CWE-352
Origin Validation Error
|
CVE-2015-2334
|
2024-11-21 11:27 |
2015-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273427
|
- |
|
mybb
|
mybb
|
Cross-site scripting (XSS) vulnerability in the MyCode editor in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2333
|
2024-11-21 11:27 |
2015-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273428
|
- |
|
mybb
|
mybb
|
Cross-site scripting (XSS) vulnerability in member.php in MyBB (aka MyBulletinBoard) before 1.8.4 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2332
|
2024-11-21 11:27 |
2015-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273429
|
- |
|
wpml
|
wpml
|
Cross-site scripting (XSS) vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to inject arbitrary web script or HTML via the target parameter in a reminder_popup acti…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2315
|
2024-11-21 11:27 |
2015-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273430
|
- |
|
wpml
|
wpml
|
SQL injection vulnerability in the WPML plugin before 3.1.9 for WordPress allows remote attackers to execute arbitrary SQL commands via the lang parameter in the HTTP Referer header in a wp-link-ajax…
|
CWE-89
SQL Injection
|
CVE-2015-2314
|
2024-11-21 11:27 |
2015-03-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|