|
276451
|
- |
|
webshophun
|
webshop_hun
|
Multiple SQL injection vulnerabilities in Webshop hun 1.062S allow remote attackers to execute arbitrary SQL commands via the (1) termid or (2) nyelv_id parameter to index.php.
|
CWE-89
SQL Injection
|
CVE-2015-2242
|
2024-11-21 11:27 |
2015-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276452
|
- |
|
fedoraproject phpmyadmin
|
fedora phpmyadmin
|
libraries/select_lang.lib.php in phpMyAdmin 4.0.x before 4.0.10.9, 4.2.x before 4.2.13.2, and 4.3.x before 4.3.11.1 includes invalid language values in unknown-language error responses that contain a…
|
CWE-200
Information Exposure
|
CVE-2015-2206
|
2024-11-21 11:27 |
2015-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276453
|
- |
|
google
|
chrome
|
Google Chrome before 41.0.2272.76, when Instant Extended mode is used, does not properly consider the interaction between the "1993 search" features and restore-from-disk RELOAD transitions, which ma…
|
CWE-19
Data Processing Errors
|
CVE-2015-2239
|
2024-11-21 11:27 |
2015-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276454
|
- |
|
canonical google
|
ubuntu_linux chrome v8
|
Multiple unspecified vulnerabilities in Google V8 before 4.1.0.21, as used in Google Chrome before 41.0.2272.76, allow attackers to cause a denial of service or possibly have other impact via unknown…
|
NVD-CWE-noinfo
|
CVE-2015-2238
|
2024-11-21 11:27 |
2015-03-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276455
|
- |
|
ninjaforms
|
ninja_forms
|
Multiple cross-site scripting (XSS) vulnerabilities in the Ninja Forms plugin before 2.8.9 for WordPress allow (1) remote attackers to inject arbitrary web script or HTML via the ninja_forms_field_1 …
|
CWE-79
Cross-site Scripting
|
CVE-2015-2220
|
2024-11-21 11:27 |
2015-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276456
|
- |
|
magic_hills
|
wonderplugin_audio_player
|
Multiple cross-site scripting (XSS) vulnerabilities in the wp_ajax_save_item function in wonderpluginaudio.php in the WonderPlugin Audio Player plugin before 2.1 for WordPress allow remote attackers …
|
CWE-79
Cross-site Scripting
|
CVE-2015-2218
|
2024-11-21 11:27 |
2015-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276457
|
- |
|
photocati_media
|
photocrati
|
SQL injection vulnerability in ecomm-sizes.php in the Photocrati theme 4.x for WordPress allows remote attackers to execute arbitrary SQL commands via the prod_id parameter.
|
CWE-89
SQL Injection
|
CVE-2015-2216
|
2024-11-21 11:27 |
2015-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276458
|
- |
|
services_single_sign-on_server_helper_project
|
services_single_sign-on_server_helper
|
Open redirect vulnerability in the Services single sign-on server helper (services_sso_server_helper) module for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct ph…
|
NVD-CWE-Other
|
CVE-2015-2215
|
2024-11-21 11:27 |
2015-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276459
|
- |
|
netcat
|
netcat
|
NetCat 5.01 and earlier allows remote attackers to obtain the installation path via the redirect_url parameter to netshop/post.php.
|
CWE-200
Information Exposure
|
CVE-2015-2214
|
2024-11-21 11:27 |
2015-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276460
|
- |
|
dlguard
|
dlguard
|
DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php.
|
CWE-200
Information Exposure
|
CVE-2015-2209
|
2024-11-21 11:27 |
2015-03-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|