|
211331
|
6.1 |
MEDIUM
Network
|
nodebb
|
nodebb
|
Controllers.outgoing in controllers/index.js in NodeBB before 0.7.3 has outgoing XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9286
|
2024-11-21 11:40 |
2019-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211332
|
6.1 |
MEDIUM
Network
|
esotalk
|
esotalk
|
esoTalk 1.0.0g4 has XSS via the PATH_INFO to the conversations/ URI.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9285
|
2024-11-21 11:40 |
2019-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211333
|
8.8 |
HIGH
Network
|
omniauth
|
omniauth
|
The request phase of the OmniAuth Ruby gem (1.9.1 and earlier) is vulnerable to Cross-Site Request Forgery when used as part of the Ruby on Rails framework, allowing accounts to be connected without …
|
CWE-352
Origin Validation Error
|
CVE-2015-9284
|
2024-11-21 11:40 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211334
|
6.1 |
MEDIUM
Network
|
grafana
|
piechart-panel
|
The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an atta…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9282
|
2024-11-21 11:40 |
2019-02-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211335
|
6.1 |
MEDIUM
Network
|
sas
|
web_infrastructure_platform
|
Logon Manager in SAS Web Infrastructure Platform before 9.4M3 allows reflected XSS on the Timeout page.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9281
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211336
|
10.0 |
CRITICAL
Network
|
mailenable
|
mailenable
|
MailEnable before 8.60 allows XXE via an XML document in the request.aspx Options parameter.
|
CWE-611
XXE
|
CVE-2015-9280
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211337
|
6.1 |
MEDIUM
Network
|
mailenable
|
mailenable
|
MailEnable before 8.60 allows Stored XSS via malformed use of "<img/src" with no ">" character in the body of an e-mail message.
|
CWE-79
Cross-site Scripting
|
CVE-2015-9279
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211338
|
9.8 |
CRITICAL
Network
|
mailenable
|
mailenable
|
MailEnable before 8.60 allows Privilege Escalation because admin accounts could be created as a consequence of %0A mishandling in AUTH.TAB after a password-change request.
|
CWE-255
Credentials Management
|
CVE-2015-9278
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211339
|
9.1 |
CRITICAL
Network
|
mailenable
|
mailenable
|
MailEnable before 8.60 allows Directory Traversal for reading the messages of other users, uploading files, and deleting files because "/../" and "/.. /" are mishandled.
|
CWE-22
Path Traversal
|
CVE-2015-9277
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211340
|
6.1 |
MEDIUM
Network
|
smartertools
|
smartermail
|
SmarterTools SmarterMail before 13.3.5535 was vulnerable to stored XSS by bypassing the anti-XSS mechanisms. It was possible to run JavaScript code when a victim user opens or replies to the attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2015-9276
|
2024-11-21 11:40 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|