|
274201
|
- |
|
fancyfon
|
famoc
|
Multiple SQL injection vulnerabilities in FancyFon FAMOC before 3.17.4 allow (1) remote attackers to execute arbitrary SQL commands via the device ID REST parameter (PATH_INFO) to /ajax.php or (2) re…
|
CWE-89
SQL Injection
|
CVE-2015-1514
|
2024-11-21 11:25 |
2015-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274202
|
- |
|
siphon
|
siphone_enterprise_pbx
|
SQL injection vulnerability in SIPhone Enterprise PBX allows remote attackers to execute arbitrary SQL commands via the Username.
|
CWE-89
SQL Injection
|
CVE-2015-1513
|
2024-11-21 11:25 |
2015-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274203
|
- |
|
fancyfon
|
famoc
|
Multiple cross-site scripting (XSS) vulnerabilities in FancyFon FAMOC before 3.17.4 allow remote attackers to inject arbitrary web script or HTML via the (1) LoginForm[username] to ui/system/login or…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1512
|
2024-11-21 11:25 |
2015-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274204
|
- |
|
fork-cms
|
fork_cms
|
Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) language[] or (2) type[] parameter to pr…
|
CWE-89
SQL Injection
|
CVE-2015-1467
|
2024-11-21 11:25 |
2015-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274205
|
- |
|
fli4l
|
fli4l
|
Multiple cross-site scripting (XSS) vulnerabilities in the web administration frontend in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allow remote attackers to inject arbitrary…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1444
|
2024-11-21 11:25 |
2015-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274206
|
- |
|
aas9
|
zerocms
|
SQL injection vulnerability in views/zero_transact_user.php in the administrative backend in ZeroCMS 1.3.3, 1.3.2, and earlier allows remote authenticated users to execute arbitrary SQL commands via …
|
CWE-89
SQL Injection
|
CVE-2015-1442
|
2024-11-21 11:25 |
2015-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274207
|
- |
|
mcafee
|
data_loss_prevention_endpoint
|
McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 …
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1305
|
2024-11-21 11:25 |
2015-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274208
|
- |
|
ansible
|
tower
|
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote attackers to bypass authentication and obtain sensitive information via a websocket connection to socket.io/1/.
|
CWE-200
Information Exposure
|
CVE-2015-1482
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274209
|
- |
|
ansible
|
tower
|
Ansible Tower (aka Ansible UI) before 2.0.5 allows remote organization administrators to gain privileges by creating a superuser account.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1481
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274210
|
- |
|
manageengine
|
servicedesk_plus
|
ZOHO ManageEngine ServiceDesk Plus (SDP) before 9.0 build 9031 allows remote authenticated users to obtain sensitive ticket information via a (1) getTicketData action to servlet/AJaxServlet or a dire…
|
CWE-200
Information Exposure
|
CVE-2015-1480
|
2024-11-21 11:25 |
2015-02-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|