|
271811
|
- |
|
refbase
|
refbase
|
Multiple open redirect vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allow remote attackers to redirect users to arbitrary web sites and co…
|
NVD-CWE-Other
|
CVE-2015-6012
|
2024-11-21 11:34 |
2015-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271812
|
- |
|
refbase
|
refbase
|
Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allows remote attackers to conduct XML injection attacks via (1) the id parameter to unapi.php or (2) the styles…
|
NVD-CWE-Other
|
CVE-2015-6011
|
2024-11-21 11:34 |
2015-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271813
|
- |
|
refbase
|
refbase
|
Multiple cross-site scripting (XSS) vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 and bleeding-edge before 2015-01-08 allow remote attackers to inject arbitrary web script or …
|
CWE-79
Cross-site Scripting
|
CVE-2015-6010
|
2024-11-21 11:34 |
2015-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271814
|
- |
|
refbase
|
refbase
|
Multiple SQL injection vulnerabilities in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary SQL commands via (1) the where parameter to rss.php or (2) the…
|
CWE-89
SQL Injection
|
CVE-2015-6009
|
2024-11-21 11:34 |
2015-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271815
|
- |
|
refbase
|
refbase
|
install.php in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to execute arbitrary commands via the adminPassword parameter, a different issue than CVE-2015-7381.
|
CWE-78
OS Command
|
CVE-2015-6008
|
2024-11-21 11:34 |
2015-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271816
|
- |
|
refbase
|
refbase
|
Cross-site request forgery (CSRF) vulnerability in Web Reference Database (aka refbase) through 0.9.6 allows remote attackers to hijack the authentication of arbitrary users.
|
CWE-352
Origin Validation Error
|
CVE-2015-6007
|
2024-11-21 11:34 |
2015-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271817
|
- |
|
everest
|
peakhmi
|
Everest PeakHMI before 8.7.0.2, when the video server is used, allows remote attackers to cause a denial of service (incorrect pointer dereference and daemon crash) via a crafted packet.
|
NVD-CWE-Other
|
CVE-2015-6454
|
2024-11-21 11:34 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271818
|
- |
|
cisco
|
anyconnect_secure_mobility_client
|
Cisco AnyConnect Secure Mobility Client 4.1(8) on OS X and Linux does not verify pathnames before installation actions, which allows local users to obtain root privileges via a crafted installation f…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-6306
|
2024-11-21 11:34 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271819
|
- |
|
cisco
|
anyconnect_secure_mobility_client
|
Untrusted search path vulnerability in the CMainThread::launchDownloader function in vpndownloader.exe in Cisco AnyConnect Secure Mobility Client 2.0 through 4.1 on Windows allows local users to gain…
|
CWE-426
Untrusted Search Path
|
CVE-2015-6305
|
2024-11-21 11:34 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271820
|
- |
|
cisco
|
wireless_lan_controller_software
|
The RADIUS functionality on Cisco Wireless LAN Controller (WLC) devices with software 7.0(250.0) and 7.0(252.0) allows remote attackers to disconnect arbitrary sessions via crafted Disconnect-Request…
|
CWE-399
Resource Management Errors
|
CVE-2015-6302
|
2024-11-21 11:34 |
2015-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|