|
211401
|
8.8 |
HIGH
Network
|
omniauth
|
omniauth
|
The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without …
|
CWE-352
Origin Validation Error
|
CVE-2015-9284
|
2024-11-21 11:40 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211402
|
6.1 |
MEDIUM
Network
|
grafana
|
piechart-panel
|
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an atta…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9282
|
2024-11-21 11:40 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211403
|
6.1 |
MEDIUM
Network
|
sas
|
web_infrastructure_platform
|
Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9281
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211404
|
10.0 |
CRITICAL
Network
|
mailenable
|
mailenable
|
MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.
|
CWE-611
XXE
|
CVE-2015-9280
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211405
|
6.1 |
MEDIUM
Network
|
mailenable
|
mailenable
|
MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9279
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211406
|
9.8 |
CRITICAL
Network
|
mailenable
|
mailenable
|
MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a password-change request.
|
CWE-255
Credentials Management
|
CVE-2015-9278
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211407
|
9.1 |
CRITICAL
Network
|
mailenable
|
mailenable
|
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.
|
CWE-22
Path Traversal
|
CVE-2015-9277
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211408
|
6.1 |
MEDIUM
Network
|
smartertools
|
smartermail
|
SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms. It was possible to run JavaScript code when a victim user opens or replies to the attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9276
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211409
|
5.3 |
MEDIUM
Network
|
arc_project
|
arc
|
ARC 5.21q allows directory traversal via a full pathname in an archive file.
|
CWE-22
Path Traversal
|
CVE-2015-9275
|
2024-11-21 11:40 |
2019-01-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211410
|
6.5 |
MEDIUM
Network
|
harfbuzz_project
|
harfbuzz
|
HarfBuzz before 1.0.4 allows remote attackers to cause a denial of service (invalid read of two bytes and application crash) because of GPOS and GSUB table mishandling, related to hb-ot-layout-gpos-t…
|
CWE-125
Out-of-bounds Read
|
CVE-2015-9274
|
2024-11-21 11:40 |
2018-11-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|