|
212291
|
- |
|
j2store
|
j2store
|
Multiple SQL injection vulnerabilities in the J2Store (com_j2store) extension before 3.1.7 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) sortby or (2) manufacturer_…
|
CWE-89
SQL Injection
|
CVE-2015-6513
|
2024-11-21 11:35 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212292
|
- |
|
codelogic
|
freichat
|
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute arbitrary SQL commands via the time parameter to se…
|
CWE-89
SQL Injection
|
CVE-2015-6512
|
2024-11-21 11:35 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212293
|
- |
|
netgate
|
pfsense
|
Cross-site scripting (XSS) vulnerability in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the server[] parameter to services_ntpd.php.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6511
|
2024-11-21 11:35 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212294
|
- |
|
netgate
|
pfsense
|
Cross-site scripting (XSS) vulnerability in pfSense before 2.2.3 allows remote attackers to inject arbitrary web script or HTML via the descr parameter in a "new" action to system_authservers.php.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6508
|
2024-11-21 11:35 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212295
|
- |
|
netgate
|
pfsense
|
Multiple cross-site scripting (XSS) vulnerabilities in pfSense before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) srctrack, (2) use_mfs_tmp_size, or (3) use_mfs_va…
|
CWE-79
Cross-site Scripting
|
CVE-2015-6510
|
2024-11-21 11:35 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212296
|
- |
|
netgate
|
pfsense
|
Multiple cross-site scripting (XSS) vulnerabilities in pfSense before 2.2.3 allow remote attackers to inject arbitrary web script or HTML via the (1) proxypass parameter to system_advanced_misc.php; …
|
CWE-79
Cross-site Scripting
|
CVE-2015-6509
|
2024-11-21 11:35 |
2015-08-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212297
|
8.8 |
HIGH
Network
|
vtiger
|
vtiger_crm
|
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.3.0 and earlier allows remote a…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-6000
|
2024-11-21 11:34 |
2020-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212298
|
9.8 |
CRITICAL
Network
|
thomsonreuters
|
fatca
|
Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter.
|
CWE-22
Path Traversal
|
CVE-2015-5952
|
2024-11-21 11:34 |
2020-01-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212299
|
9.9 |
CRITICAL
Network
|
thomsonreuters
|
fatca
|
A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute system commands.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-5951
|
2024-11-21 11:34 |
2020-01-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212300
|
5.4 |
MEDIUM
Network
|
edx
|
edx-platform
|
edx-platform before 2015-08-17 allows XSS in the Studio listing of courses.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6253
|
2024-11-21 11:34 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|