|
212071
|
8.1 |
HIGH
Network
|
pgbouncer
|
pgbouncer
|
PgBouncer 1.6.x before 1.6.1, when configured with auth_user, allows remote attackers to gain login access as auth_user via an unknown username.
|
CWE-287
Improper Authentication
|
CVE-2015-6817
|
2024-11-21 11:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212072
|
7.5 |
HIGH
Network
|
huawei
|
wlan_acu2_firmware wlan_ac6005_firmware wlan_ac6605_firmware
|
The mDNS module in Huawei WLAN AC6005, AC6605, and ACU2 devices with software before V200R006C00SPC100 allows remote attackers to obtain sensitive information by leveraging failure to restrict proces…
|
CWE-200
Information Exposure
|
CVE-2015-6586
|
2024-11-21 11:35 |
2017-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212073
|
8.8 |
HIGH
Network
|
wolfcms
|
wolf_cms
|
Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" …
|
CWE-20
Improper Input Validation
|
CVE-2015-6568
|
2024-11-21 11:35 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212074
|
8.8 |
HIGH
Network
|
wolfcms
|
wolf_cms
|
Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exp…
|
CWE-20
Improper Input Validation
|
CVE-2015-6567
|
2024-11-21 11:35 |
2017-04-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212075
|
9.8 |
CRITICAL
Network
|
inspircd debian
|
inspircd debian_linux
|
Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This issue exists as an additional issue from an incomplet…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2015-6674
|
2024-11-21 11:35 |
2017-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212076
|
5.9 |
MEDIUM
Network
|
edx
|
edx-platform
|
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveragi…
|
CWE-200
Information Exposure
|
CVE-2015-6671
|
2024-11-21 11:35 |
2017-03-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212077
|
6.1 |
MEDIUM
Network
|
puppet
|
puppet_enterprise
|
Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the string parameter.
|
CWE-601
Open Redirect
|
CVE-2015-6501
|
2024-11-21 11:35 |
2017-01-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212078
|
7.5 |
HIGH
Network
|
sisco
|
mms-ease_firmware ax-s4_iccp_firmware
|
The SNAP Lite component in certain SISCO MMS-EASE and AX-S4 ICCP products allows remote attackers to cause a denial of service (CPU consumption) via a crafted packet.
|
CWE-399
Resource Management Errors
|
CVE-2015-6574
|
2024-11-21 11:35 |
2016-12-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212079
|
6.1 |
MEDIUM
Network
|
vmware
|
vcenter_server
|
Cross-site scripting (XSS) vulnerability in the vSphere Web Client in VMware vCenter Server 5.0 before U3g, 5.1 before U3d, and 5.5 before U2d allows remote attackers to inject arbitrary web script o…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6931
|
2024-11-21 11:35 |
2016-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212080
|
7.5 |
HIGH
Network
|
php xmlsoft
|
php libxml2
|
The xsl_ext_function_php function in ext/xsl/xsltprocessor.c in PHP before 5.4.45, 5.5.x before 5.5.29, and 5.6.x before 5.6.13, when libxml2 before 2.9.2 is used, does not consider the possibility o…
|
NVD-CWE-Other
|
CVE-2015-6838
|
2024-11-21 11:35 |
2016-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|