|
267081
|
8.8 |
HIGH
Network
|
hiniarata
|
casebook_plugin
|
Cross-site request forgery (CSRF) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators.
|
CWE-352
Origin Validation Error
|
CVE-2016-1174
|
2024-11-21 11:45 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267082
|
6.1 |
MEDIUM
Network
|
hiniarata
|
casebook_plugin
|
Cross-site scripting (XSS) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1173
|
2024-11-21 11:45 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267083
|
8.8 |
HIGH
Network
|
hiniarata
|
casebook_plugin
|
Cross-site request forgery (CSRF) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators.
|
CWE-352
Origin Validation Error
|
CVE-2016-1172
|
2024-11-21 11:45 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267084
|
6.1 |
MEDIUM
Network
|
hiniarata
|
casebook_plugin
|
Cross-site scripting (XSS) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1171
|
2024-11-21 11:45 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267085
|
8.8 |
HIGH
Network
|
hiniarata
|
casebook_plugin
|
Cross-site request forgery (CSRF) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to hijack the authentication of administrators.
|
CWE-352
Origin Validation Error
|
CVE-2016-1170
|
2024-11-21 11:45 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267086
|
6.1 |
MEDIUM
Network
|
hiniarata
|
casebook_plugin
|
Cross-site scripting (XSS) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1169
|
2024-11-21 11:45 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267087
|
6.1 |
MEDIUM
Network
|
falconsc
|
wisepoint_authenticator wisepoint
|
The management screen in Falcon WisePoint 4.3.1 and earlier and WisePoint Authenticator 4.1.19.22 and earlier allows remote attackers to conduct clickjacking attacks via unspecified vectors.
|
CWE-254
7PK - Security Features
|
CVE-2016-1177
|
2024-11-21 11:45 |
2016-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267088
|
6.3 |
MEDIUM
Network
|
sharp
|
eva_animator
|
Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a crafted web page.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1176
|
2024-11-21 11:45 |
2016-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267089
|
4.3 |
MEDIUM
Network
|
sharp
|
aquos_hn-pp150_firmware
|
Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remote attackers to hijack the authentication of arbitrary users.
|
CWE-352
Origin Validation Error
|
CVE-2016-1175
|
2024-11-21 11:45 |
2016-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267090
|
8.8 |
HIGH
Network
|
aterm
|
wf800hp_firmware
|
Cross-site request forgery (CSRF) vulnerability on NEC Aterm WF800HP devices with firmware 1.0.17 and earlier allows remote attackers to hijack the authentication of arbitrary users.
|
CWE-352
Origin Validation Error
|
CVE-2016-1168
|
2024-11-21 11:45 |
2016-04-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|