|
211561
|
- |
|
bisonware
|
bisonftp
|
Directory traversal vulnerability in BisonWare BisonFTP 3.5 allows remote attackers to read arbitrary files via a ../ (dot dot slash) in a RETR command.
|
CWE-22
Path Traversal
|
CVE-2015-7602
|
2024-11-21 11:37 |
2015-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211562
|
- |
|
pcman\'s_ftp_server_project
|
pcman\'s_ftp_server
|
Directory traversal vulnerability in PCMan's FTP Server 2.0.7 allows remote attackers to read arbitrary files via a ..// (dot dot double slash) in a RETR command.
|
CWE-22
Path Traversal
|
CVE-2015-7601
|
2024-11-21 11:37 |
2015-09-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211563
|
7.5 |
HIGH
Network
|
lenovo
|
system_update
|
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and p…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2015-7336
|
2024-11-21 11:36 |
2020-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211564
|
7.0 |
HIGH
Local
|
lenovo
|
system_update
|
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and …
|
CWE-362
Race Condition
|
CVE-2015-7335
|
2024-11-21 11:36 |
2020-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211565
|
7.8 |
HIGH
Local
|
lenovo
|
system_update
|
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Upd…
|
CWE-269
Improper Privilege Management
|
CVE-2015-7334
|
2024-11-21 11:36 |
2020-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211566
|
7.8 |
HIGH
Local
|
lenovo
|
system_update
|
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Upd…
|
CWE-269
Improper Privilege Management
|
CVE-2015-7333
|
2024-11-21 11:36 |
2020-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211567
|
7.2 |
HIGH
Network
|
joobi
|
jnews
|
JNews Joomla Component before 8.5.0 allows SQL injection via upload thumbnail, Queue Search Field, Subscribers Search Field, or Newsletters Search Field.
|
CWE-89
SQL Injection
|
CVE-2015-7342
|
2024-11-21 11:36 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211568
|
8.8 |
HIGH
Network
|
joobi
|
jnews
|
JNews Joomla Component before 8.5.0 allows arbitrary File Upload via Subscribers or Templates, as demonstrated by the .php5 extension.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-7341
|
2024-11-21 11:36 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211569
|
7.2 |
HIGH
Network
|
gwesystems
|
jevents
|
JEvents Joomla Component before 3.4.0 RC6 has SQL Injection via evid in a Manage Events action.
|
CWE-89
SQL Injection
|
CVE-2015-7340
|
2024-11-21 11:36 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211570
|
8.8 |
HIGH
Network
|
widgetfactorylimited
|
jce
|
JCE Joomla Component 2.5.0 to 2.5.2 allows arbitrary file upload via a .php file extension for an image file to the /com_jce/editor/libraries/classes/browser.php script.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-7339
|
2024-11-21 11:36 |
2020-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|