|
277701
|
- |
|
10web
|
photo_gallery
|
SQL injection vulnerability in the Photo Gallery plugin 1.2.7 for WordPress allows remote attackers to execute arbitrary SQL commands via the order_by parameter in a GalleryBox action to wp-admin/adm…
|
CWE-89
SQL Injection
|
CVE-2015-1055
|
2024-11-21 11:24 |
2015-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277702
|
- |
|
crea8social
|
crea8social
|
Cross-site scripting (XSS) vulnerability in the Games feature in Crea8Social 2.0 allows remote authenticated users to inject arbitrary web script or HTML via the Game Content field in Add Game.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1054
|
2024-11-21 11:24 |
2015-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277703
|
- |
|
croogo
|
croogo
|
Cross-site scripting (XSS) vulnerability in the administrative backend in Croogo before 2.2.1 allows remote attackers to inject arbitrary web script or HTML via the path parameter to admin/file_manag…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1053
|
2024-11-21 11:24 |
2015-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277704
|
- |
|
phpkit
|
phpkit
|
Cross-site scripting (XSS) vulnerability in the poll archive in PHPKIT 1.6.6 (Build 160014) allows remote attackers to inject arbitrary web script or HTML via the result parameter to upload_files/pk/…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1052
|
2024-11-21 11:24 |
2015-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277705
|
- |
|
context_project fedoraproject
|
context fedora
|
Open redirect vulnerability in the Context UI module in the Context module 7.x-3.x before 7.x-3.6 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing atta…
|
NVD-CWE-Other
|
CVE-2015-1051
|
2024-11-21 11:24 |
2015-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277706
|
- |
|
f5
|
big-ip_application_security_manager
|
Cross-site scripting (XSS) vulnerability in F5 BIG-IP Application Security Manager (ASM) before 11.6 allows remote attackers to inject arbitrary web script or HTML via the Response Body field when cr…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1050
|
2024-11-21 11:24 |
2015-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277707
|
- |
|
e107
|
e107
|
Cross-site scripting (XSS) vulnerability in e107_admin/filemanager.php in e107 1.0.4 allows remote attackers to inject arbitrary web script or HTML via the e107_files/ file path in the QUERY_STRING.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1041
|
2024-11-21 11:24 |
2015-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277708
|
- |
|
bedita
|
bedita
|
Multiple cross-site scripting (XSS) vulnerabilities in the administrative backend in BEdita 3.4.0 allow remote authenticated users to inject arbitrary web script or HTML via the (1) lrealname field i…
|
CWE-79
Cross-site Scripting
|
CVE-2015-1040
|
2024-11-21 11:24 |
2015-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277709
|
- |
|
zfcuser_project
|
zfcuser
|
Cross-site scripting (XSS) vulnerability in user/login.phtml in ZF-Commons ZfcUser before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the redirect parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2015-1039
|
2024-11-21 11:24 |
2015-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277710
|
- |
|
mcafee
|
epolicy_orchestrator
|
McAfee ePolicy Orchestrator (ePO) before 4.6.9 and 5.x before 5.1.2 uses the same secret key across different customers' installations, which allows attackers to obtain the administrator password by …
|
CWE-200
Information Exposure
|
CVE-2015-0922
|
2024-11-21 11:24 |
2015-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|