|
212441
|
9.9 |
CRITICAL
Network
|
thomsonreuters
|
fatca
|
A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute system commands.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-5951
|
2024-11-21 11:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212442
|
5.4 |
MEDIUM
Network
|
edx
|
edx-platform
|
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6253
|
2024-11-21 11:34 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212443
|
9.8 |
CRITICAL
Network
|
tripwire
|
ip360
|
The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP…
|
CWE-287
Improper Authentication
|
CVE-2015-6237
|
2024-11-21 11:34 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212444
|
5.9 |
MEDIUM
Network
|
cisco
|
rv320_firmware rv325_firmware rvs4000_firmware wrv210_firmware wap4410n_firmware wrv200_firmware wrvs4400n_firmware wap200_firmware wvc2300_firmware pvc2300_firmware srw…
|
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct ma…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-6358
|
2024-11-21 11:34 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212445
|
5.3 |
MEDIUM
Network
|
simple-php-captcha_project
|
simple-php-captcha
|
simple-php-captcha before commit 9d65a945029c7be7bb6bc893759e74c5636be694 allows remote attackers to automatically generate the captcha response by running the same code on the client-side.
|
CWE-200
Information Exposure
|
CVE-2015-6250
|
2024-11-21 11:34 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212446
|
9.8 |
CRITICAL
Network
|
froxlor
|
froxlor
|
Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.log.
|
CWE-200
Information Exposure
|
CVE-2015-5959
|
2024-11-21 11:34 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212447
|
8.1 |
HIGH
Network
|
salesagility
|
suitecrm
|
Race condition in SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5947.
|
CWE-362
Race Condition
|
CVE-2015-5948
|
2024-11-21 11:34 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212448
|
8.1 |
HIGH
Network
|
salesagility
|
suitecrm
|
SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code.
|
CWE-362
Race Condition
|
CVE-2015-5947
|
2024-11-21 11:34 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212449
|
8.8 |
HIGH
Network
|
phpfilemanager_project
|
phpfilemanager
|
phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.
|
CWE-78
OS Command
|
CVE-2015-5958
|
2024-11-21 11:34 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212450
|
7.8 |
HIGH
Local
|
sugarcrm
|
sugarcrm
|
Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.
|
CWE-184
Incomplete Blacklist
|
CVE-2015-5946
|
2024-11-21 11:34 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|