|
276741
|
- |
|
apache
|
camel
|
XML external entity (XXE) vulnerability in the XML converter setup in converter/jaxp/XmlConverter.java in Apache Camel before 2.13.4 and 2.14.x before 2.14.2 allows remote attackers to read arbitrary…
|
NVD-CWE-Other
|
CVE-2015-0263
|
2024-11-21 11:22 |
2015-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276742
|
- |
|
moodle
|
moodle
|
Cross-site request forgery (CSRF) vulnerability in auth/shibboleth/logout.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote attackers to hijack…
|
CWE-352
Origin Validation Error
|
CVE-2015-0218
|
2024-11-21 11:22 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276743
|
- |
|
moodle
|
moodle
|
filter/mediaplugin/filter.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to cause a denial of service (CPU consumption o…
|
CWE-399
Resource Management Errors
|
CVE-2015-0217
|
2024-11-21 11:22 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276744
|
- |
|
moodle
|
moodle
|
access.php in the Lesson module in Moodle 2.8.x before 2.8.2 does not set the RISK_XSS bit for graders, which allows remote authenticated users to conduct cross-site scripting (XSS) attacks via craft…
|
CWE-79
Cross-site Scripting
|
CVE-2015-0216
|
2024-11-21 11:22 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276745
|
- |
|
moodle
|
moodle
|
calendar/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to obtain sensitive calendar-event information via a…
|
CWE-200
Information Exposure
|
CVE-2015-0215
|
2024-11-21 11:22 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276746
|
- |
|
moodle
|
moodle
|
message/externallib.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to bypass a messaging-disabled setting via a web-serv…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2015-0214
|
2024-11-21 11:22 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276747
|
- |
|
moodle
|
moodle
|
Multiple cross-site request forgery (CSRF) vulnerabilities in (1) editcategories.html and (2) editcategories.php in the Glossary module in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4…
|
CWE-352
Origin Validation Error
|
CVE-2015-0213
|
2024-11-21 11:22 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276748
|
- |
|
moodle
|
moodle
|
Cross-site scripting (XSS) vulnerability in course/pending.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 allows remote authenticated users to inject arbi…
|
CWE-79
Cross-site Scripting
|
CVE-2015-0212
|
2024-11-21 11:22 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276749
|
- |
|
moodle
|
moodle
|
mod/lti/ajax.php in Moodle through 2.5.9, 2.6.x before 2.6.7, 2.7.x before 2.7.4, and 2.8.x before 2.8.2 does not consider the moodle/course:manageactivities and mod/lti:addinstance capabilities befo…
|
CWE-200
Information Exposure
|
CVE-2015-0211
|
2024-11-21 11:22 |
2015-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276750
|
- |
|
ibm
|
business_process_manager websphere
|
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x throu…
|
CWE-79
Cross-site Scripting
|
CVE-2015-0193
|
2024-11-21 11:22 |
2015-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|