|
274921
|
7.5 |
HIGH
Network
|
netty playframework lightbend
|
netty play_framework
|
Netty before 3.9.8.Final, 3.10.x before 3.10.3.Final, 4.0.x before 4.0.28.Final, and 4.1.x before 4.1.0.Beta5 and Play Framework 2.x before 2.3.9 might allow remote attackers to bypass the httpOnly f…
|
CWE-20
Improper Input Validation
|
CVE-2015-2156
|
2024-11-21 11:26 |
2017-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274922
|
4.8 |
MEDIUM
Network
|
phpbugtracker_project
|
phpbugtracker
|
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.2 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2148
|
2024-11-21 11:26 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274923
|
9.8 |
CRITICAL
Network
|
phpbugtracker_project
|
phpbugtracker
|
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via unspecified parameters.
|
CWE-89
SQL Injection
|
CVE-2015-2147
|
2024-11-21 11:26 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274924
|
9.8 |
CRITICAL
Network
|
phpbugtracker_project
|
phpbugtracker
|
Multiple SQL injection vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to project.php, the (2) group_id pa…
|
CWE-89
SQL Injection
|
CVE-2015-2146
|
2024-11-21 11:26 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274925
|
4.8 |
MEDIUM
Network
|
phpbugtracker_project
|
phpbugtracker
|
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2015-2145
|
2024-11-21 11:26 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274926
|
4.8 |
MEDIUM
Network
|
phpbugtracker_project
|
phpbugtracker
|
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) project name paramet…
|
CWE-79
Cross-site Scripting
|
CVE-2015-2144
|
2024-11-21 11:26 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274927
|
8.8 |
HIGH
Network
|
phpbugtracker_project
|
phpbugtracker
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to hijack the authentication of users for requests that cause an unspecifi…
|
CWE-352
Origin Validation Error
|
CVE-2015-2143
|
2024-11-21 11:26 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274928
|
8.0 |
HIGH
Network
|
phpbugtracker_project
|
phpbugtracker
|
Multiple cross-site request forgery (CSRF) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote authenticated users to (1) hijack the authentication of users for requests that caus…
|
CWE-352
Origin Validation Error
|
CVE-2015-2142
|
2024-11-21 11:26 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274929
|
5.9 |
MEDIUM
Network
|
http.rb_project
|
http.rb
|
The Ruby http gem before 0.7.3 does not verify hostnames in SSL connections, which might allow remote attackers to obtain sensitive information via a man-in-the-middle-attack.
|
CWE-200
Information Exposure
|
CVE-2015-1828
|
2024-11-21 11:26 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274930
|
7.8 |
HIGH
Local
|
pngcrush_project
|
pngcrush
|
Off-by-one error in the pngcrush_measure_idat function in pngcrush.c in pngcrush before 1.7.84 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary c…
|
CWE-189
Numeric Errors
|
CVE-2015-2158
|
2024-11-21 11:26 |
2017-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|