|
211471
|
5.3 |
MEDIUM
Network
|
datto
|
alto_3_firmware alto_2_firmware alto_xl_firmware siris_3_firmware siris_2_firmware siris_3_x_all-flash_firmware siris_virtual_firmware alto_imaged_firmware
|
Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default.
|
CWE-200
Information Exposure
|
CVE-2015-9256
|
2024-11-21 11:40 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211472
|
5.3 |
MEDIUM
Network
|
datto
|
alto_3_firmware alto_2_firmware alto_xl_firmware siris_3_firmware siris_2_firmware siris_3_x_all-flash_firmware siris_virtual_firmware alto_imaged_firmware
|
Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory.
|
CWE-200
Information Exposure
|
CVE-2015-9255
|
2024-11-21 11:40 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211473
|
9.8 |
CRITICAL
Network
|
datto
|
alto_3_firmware alto_2_firmware alto_xl_firmware siris_3_firmware siris_2_firmware siris_3_x_all-flash_firmware siris_virtual_firmware alto_imaged_firmware
|
Datto ALTO and SIRIS devices have a default VNC password.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2015-9254
|
2024-11-21 11:40 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211474
|
6.5 |
MEDIUM
Network
|
php
|
php
|
An issue was discovered in PHP 7.3.x before 7.3.0alpha3, 7.2.x before 7.2.8, and before 7.1.20. The php-fpm master process restarts a child process in an endless loop when using program execution fun…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2015-9253
|
2024-11-21 11:40 |
2018-02-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211475
|
5.5 |
MEDIUM
Local
|
qpdf_project
|
qpdf
|
An issue was discovered in QPDF before 7.0.0. Endless recursion causes stack exhaustion in QPDFTokenizer::resolveLiteral() in QPDFTokenizer.cc, related to the QPDF::resolve function in QPDF.cc.
|
CWE-399
Resource Management Errors
|
CVE-2015-9252
|
2024-11-21 11:40 |
2018-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211476
|
6.1 |
MEDIUM
Network
|
jquery oracle
|
jquery service_bus primavera_unifier jd_edwards_enterpriseone_tools enterprise_manager_ops_center webcenter_sites weblogic_server jdeveloper primavera_gateway peoplesoft_en…
|
jQuery before 3.0.0 is vulnerable to Cross-site Scripting (XSS) attacks when a cross-domain Ajax request is performed without the dataType option, causing text/javascript responses to be executed.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9251
|
2024-11-21 11:40 |
2018-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211477
|
7.5 |
HIGH
Network
|
skyboxsecurity
|
skybox_platform
|
An issue was discovered in Skybox Platform before 7.5.201. Directory Traversal exists in /skyboxview/webskybox/attachmentdownload and /skyboxview/webskybox/filedownload via the tempFileName parameter.
|
CWE-22
Path Traversal
|
CVE-2015-9250
|
2024-11-21 11:40 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211478
|
9.8 |
CRITICAL
Network
|
skyboxsecurity
|
skybox_platform
|
An issue was discovered in Skybox Platform before 7.5.201. SQL Injection exists in /skyboxview/webservice/services/VersionWebService via a soapenv:Body element.
|
CWE-89
SQL Injection
|
CVE-2015-9249
|
2024-11-21 11:40 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211479
|
5.4 |
MEDIUM
Network
|
skyboxsecurity
|
skybox_platform
|
An issue was discovered in Skybox Platform before 7.5.201. Stored cross-site scripting vulnerabilities exist in the title, Comments, or Description field to /skyboxview/webskybox/tickets in Change Ma…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9248
|
2024-11-21 11:40 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211480
|
5.4 |
MEDIUM
Network
|
skyboxsecurity
|
skybox_platform
|
An issue was discovered in Skybox Platform before 7.5.401. Reflected cross-site scripting vulnerabilities exist in /skyboxview/webservice/services/VersionRepositoryWebService via a soapenv:Body eleme…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9247
|
2024-11-21 11:40 |
2018-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|