|
281651
|
6.1 |
MEDIUM
Network
|
filedownload_project
|
filedownload
|
XSS in filedownload v1.4 wordpress plugin
|
CWE-79
Cross-site Scripting
|
CVE-2015-1000004
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281652
|
9.8 |
CRITICAL
Network
|
filedownload_project
|
filedownload
|
Blind SQL Injection in filedownload v1.4 wordpress plugin
|
CWE-89
SQL Injection
|
CVE-2015-1000003
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281653
|
8.2 |
HIGH
Network
|
filedownload_project
|
filedownload
|
Open Proxy in filedownload v1.4 wordpress plugin
|
CWE-20
Improper Input Validation
|
CVE-2015-1000002
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281654
|
9.8 |
CRITICAL
Network
|
fast-image-adder_project
|
fast-image-adder
|
Remote file upload vulnerability in fast-image-adder v1.1 Wordpress plugin
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-1000001
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281655
|
9.8 |
CRITICAL
Network
|
mailcwp_project
|
mailcwp
|
Remote file upload vulnerability in mailcwp v1.99 wordpress plugin
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-1000000
|
2024-11-21 11:24 |
2016-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281656
|
- |
|
ininet_solutions
|
scada_web_server
|
IniNet embeddedWebServer (aka eWebServer) before 2.02 for Windows CE uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information via unspecified vect…
|
CWE-200
Information Exposure
|
CVE-2015-1005
|
2024-11-21 11:24 |
2015-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281657
|
- |
|
ininet_solutions
|
scada_web_server
|
Directory traversal vulnerability in IniNet embeddedWebServer (aka eWebServer) before 2.02 allows remote attackers to read arbitrary files via a crafted pathname.
|
CWE-22
Path Traversal
|
CVE-2015-1003
|
2024-11-21 11:24 |
2015-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281658
|
- |
|
ininet_solutions
|
scada_web_server
|
IniNet embeddedWebServer (aka eWebServer) before 2.02 mishandles URL encoding, which allows remote attackers to write to or delete files via a crafted string.
|
NVD-CWE-Other
|
CVE-2015-1002
|
2024-11-21 11:24 |
2015-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281659
|
- |
|
ininet_solutions
|
scada_web_server
|
Multiple stack-based buffer overflows in IniNet embeddedWebServer (aka eWebServer) before 2.02 allow remote attackers to execute arbitrary code via a long field in an HTTP request.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-1001
|
2024-11-21 11:24 |
2015-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281660
|
- |
|
vmware
|
vcenter_server
|
vpxd in VMware vCenter Server 5.0 before u3e, 5.1 before u3, and 5.5 before u2 allows remote attackers to cause a denial of service via a long heartbeat message.
|
CWE-20
Improper Input Validation
|
CVE-2015-1047
|
2024-11-21 11:24 |
2015-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|