|
268951
|
6.1 |
MEDIUM
Network
|
cyber-will
|
social-button_premium
|
Cross-site scripting (XSS) vulnerability in the Cyber-Will Social-button Premium plugin before 1.1 for EC-CUBE 2.13.x allows remote attackers to inject arbitrary web script or HTML via unspecified ve…
|
CWE-79
Cross-site Scripting
|
CVE-2016-1180
|
2024-11-21 11:45 |
2016-04-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268952
|
8.8 |
HIGH
Network
|
hiniarata
|
casebook_plugin
|
Cross-site request forgery (CSRF) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators.
|
CWE-352
Origin Validation Error
|
CVE-2016-1174
|
2024-11-21 11:45 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268953
|
6.1 |
MEDIUM
Network
|
hiniarata
|
casebook_plugin
|
Cross-site scripting (XSS) vulnerability in the Menubook plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1173
|
2024-11-21 11:45 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268954
|
8.8 |
HIGH
Network
|
hiniarata
|
casebook_plugin
|
Cross-site request forgery (CSRF) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to hijack the authentication of administrators.
|
CWE-352
Origin Validation Error
|
CVE-2016-1172
|
2024-11-21 11:45 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268955
|
6.1 |
MEDIUM
Network
|
hiniarata
|
casebook_plugin
|
Cross-site scripting (XSS) vulnerability in the Recruit plugin before 0.9.3 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1171
|
2024-11-21 11:45 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268956
|
8.8 |
HIGH
Network
|
hiniarata
|
casebook_plugin
|
Cross-site request forgery (CSRF) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to hijack the authentication of administrators.
|
CWE-352
Origin Validation Error
|
CVE-2016-1170
|
2024-11-21 11:45 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268957
|
6.1 |
MEDIUM
Network
|
hiniarata
|
casebook_plugin
|
Cross-site scripting (XSS) vulnerability in the Casebook plugin before 0.9.4 for baserCMS allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2016-1169
|
2024-11-21 11:45 |
2016-04-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268958
|
6.1 |
MEDIUM
Network
|
falconsc
|
wisepoint_authenticator wisepoint
|
The management screen in Falcon WisePoint 4.3.1 and earlier and WisePoint Authenticator 4.1.19.22 and earlier allows remote attackers to conduct clickjacking attacks via unspecified vectors.
|
CWE-254
7PK - Security Features
|
CVE-2016-1177
|
2024-11-21 11:45 |
2016-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268959
|
6.3 |
MEDIUM
Network
|
sharp
|
eva_animator
|
Buffer overflow in the ActiveX control in Sharp EVA Animeter allows remote attackers to execute arbitrary code via a crafted web page.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2016-1176
|
2024-11-21 11:45 |
2016-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268960
|
4.3 |
MEDIUM
Network
|
sharp
|
aquos_hn-pp150_firmware
|
Cross-site request forgery (CSRF) vulnerability in AQUOS Photo Player HN-PP150 1.02.00.04 through 1.03.01.04 allows remote attackers to hijack the authentication of arbitrary users.
|
CWE-352
Origin Validation Error
|
CVE-2016-1175
|
2024-11-21 11:45 |
2016-04-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|