|
274251
|
- |
|
jakweb
|
gecko_cms
|
Cross-site request forgery (CSRF) vulnerability in Gecko CMS 2.2 and 2.3 allows remote attackers to hijack the authentication of administrators for requests that add an administrator user via a newus…
|
CWE-352
Origin Validation Error
|
CVE-2015-1424
|
2024-11-21 11:25 |
2015-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274252
|
- |
|
jakweb
|
gecko_cms
|
Multiple SQL injection vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote administrators to execute arbitrary SQL commands via the (1) jak_delete_log[] or (2) ssp parameter to admin/index.php.
|
CWE-89
SQL Injection
|
CVE-2015-1423
|
2024-11-21 11:25 |
2015-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274253
|
- |
|
jakweb
|
gecko_cms
|
Multiple cross-site scripting (XSS) vulnerabilities in Gecko CMS 2.2 and 2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) horder[], (2) jak_catid, (3) jak_content, (4) ja…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1422
|
2024-11-21 11:25 |
2015-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274254
|
- |
|
opensuse vsftpd_project
|
opensuse vsftpd
|
Unspecified vulnerability in vsftpd 3.0.2 and earlier allows remote attackers to bypass access restrictions via unknown vectors, related to deny_file parsing.
|
NVD-CWE-noinfo
|
CVE-2015-1419
|
2024-11-21 11:25 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274255
|
- |
|
pixabay_images_project
|
pixabay_images
|
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not validate hostnames, which allows remote authenticated users to write to arbitrary files via an upload URL with a host…
|
CWE-284
Improper Access Control
|
CVE-2015-1376
|
2024-11-21 11:25 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274256
|
- |
|
pixabay_images_project
|
pixabay_images
|
pixabay-images.php in the Pixabay Images plugin before 2.4 for WordPress does not properly restrict access to the upload functionality, which allows remote attackers to write to arbitrary files.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-1375
|
2024-11-21 11:25 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274257
|
- |
|
ferretcms_project
|
ferretcms
|
Multiple cross-site request forgery (CSRF) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to hijack the authentication of administrators for requests that conduct (1) cr…
|
CWE-352
Origin Validation Error
|
CVE-2015-1374
|
2024-11-21 11:25 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274258
|
- |
|
ferretcms_project
|
ferretcms
|
Multiple cross-site scripting (XSS) vulnerabilities in admin.php in ferretCMS 1.0.4-alpha allow remote attackers to inject arbitrary web script or HTML via the (1) action parameter in a search reques…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1373
|
2024-11-21 11:25 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274259
|
- |
|
ferretcms_project
|
ferretcms
|
SQL injection vulnerability in ferretCMS 1.0.4-alpha allows remote attackers to execute arbitrary SQL commands via the p parameter in an update action to admin.php.
|
CWE-89
SQL Injection
|
CVE-2015-1372
|
2024-11-21 11:25 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274260
|
- |
|
ferretcms_project
|
ferretcms
|
Unrestricted file upload vulnerability in ferretCMS 1.0.4-alpha allows remote administrators to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct…
|
CWE-20
Improper Input Validation
|
CVE-2015-1371
|
2024-11-21 11:25 |
2015-01-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|