|
265641
|
4.3 |
MEDIUM
Network
|
ecava
|
integraxor
|
Ecava IntegraXor before 5.0 build 4522 does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive inf…
|
CWE-200
Information Exposure
|
CVE-2016-2304
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265642
|
5.3 |
MEDIUM
Network
|
ecava
|
integraxor
|
CRLF injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attacks via a crafted URL.
|
NVD-CWE-Other
|
CVE-2016-2303
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265643
|
5.3 |
MEDIUM
Network
|
ecava
|
integraxor
|
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to obtain sensitive information by reading detailed error messages.
|
CWE-200
Information Exposure
|
CVE-2016-2302
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265644
|
6.3 |
MEDIUM
Network
|
ecava
|
integraxor
|
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2016-2301
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265645
|
6.5 |
MEDIUM
Network
|
ecava
|
integraxor
|
Ecava IntegraXor before 5.0 build 4522 allows remote attackers to bypass authentication and access unspecified web pages via unknown vectors.
|
CWE-287
Improper Authentication
|
CVE-2016-2300
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265646
|
7.3 |
HIGH
Network
|
ecava
|
integraxor
|
SQL injection vulnerability in Ecava IntegraXor before 5.0 build 4522 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2016-2299
|
2024-11-21 11:48 |
2016-04-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265647
|
7.5 |
HIGH
Network
|
accuenergy
|
acuvim_ii_net_firmware acuvim_iir_net_firmware
|
The AXM-NET module in Accuenergy Acuvim II NET Firmware 3.08 and Acuvim IIR NET Firmware 3.08 allows remote attackers to discover a cleartext mail-server password via unspecified vectors.
|
CWE-200
Information Exposure
|
CVE-2016-2294
|
2024-11-21 11:48 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265648
|
8.6 |
HIGH
Network
|
accuenergy
|
acuvim_iir_net_firmware acuvim_ii_net_firmware
|
The AXM-NET module in Accuenergy Acuvim II NET Firmware 3.08 and Acuvim IIR NET Firmware 3.08 allows remote attackers to discover settings via a direct request to an unspecified URL.
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2293
|
2024-11-21 11:48 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265649
|
7.5 |
HIGH
Network
|
honeywell
|
uniformance_process_history_database
|
Buffer overflow in RDISERVER in Honeywell Uniformance Process History Database (PHD) R310, R320, and R321 allows remote attackers to cause a denial of service (service outage) via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-2280
|
2024-11-21 11:48 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265650
|
5.5 |
MEDIUM
Local
|
symantec
|
altiris_it_management_suite
|
The Inventory Solution component in the Management Agent in the client in Symantec Altiris IT Management Suite (ITMS) through 7.6 HF7 allows local users to bypass intended application-blacklist restr…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2016-2202
|
2024-11-21 11:48 |
2016-04-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|