|
212301
|
9.8 |
CRITICAL
Network
|
tripwire
|
ip360
|
The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP…
|
CWE-287
Improper Authentication
|
CVE-2015-6237
|
2024-11-21 11:34 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212302
|
5.9 |
MEDIUM
Network
|
cisco
|
rv320_firmware rv325_firmware rvs4000_firmware wrv210_firmware wap4410n_firmware wrv200_firmware wrvs4400n_firmware wap200_firmware wvc2300_firmware pvc2300_firmware srw…
|
Multiple Cisco embedded devices use hardcoded X.509 certificates and SSH host keys embedded in the firmware, which allows remote attackers to defeat cryptographic protection mechanisms and conduct ma…
|
CWE-295
Improper Certificate Validation
|
CVE-2015-6358
|
2024-11-21 11:34 |
2017-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212303
|
5.3 |
MEDIUM
Network
|
simple-php-captcha_project
|
simple-php-captcha
|
simple-php-captcha before commit 9d65a945029c7be7bb6bc893759e74c5636be694 allows remote attackers to automatically generate the captcha response by running the same code on the client-side.
|
CWE-200
Information Exposure
|
CVE-2015-6250
|
2024-11-21 11:34 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212304
|
9.8 |
CRITICAL
Network
|
froxlor
|
froxlor
|
Froxlor before 0.9.33.2 with the default configuration/setup might allow remote attackers to obtain the database password by reading /logs/sql-error.log.
|
CWE-200
Information Exposure
|
CVE-2015-5959
|
2024-11-21 11:34 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212305
|
8.1 |
HIGH
Network
|
salesagility
|
suitecrm
|
Race condition in SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code. NOTE: this vulnerability exists because of an incomplete fix for CVE-2015-5947.
|
CWE-362
Race Condition
|
CVE-2015-5948
|
2024-11-21 11:34 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212306
|
8.1 |
HIGH
Network
|
salesagility
|
suitecrm
|
SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code.
|
CWE-362
Race Condition
|
CVE-2015-5947
|
2024-11-21 11:34 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212307
|
8.8 |
HIGH
Network
|
phpfilemanager_project
|
phpfilemanager
|
phpFileManager 0.9.8 allows remote attackers to execute arbitrary commands via a crafted URL.
|
CWE-78
OS Command
|
CVE-2015-5958
|
2024-11-21 11:34 |
2017-09-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212308
|
7.8 |
HIGH
Local
|
sugarcrm
|
sugarcrm
|
Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.
|
CWE-184
Incomplete Blacklist
|
CVE-2015-5946
|
2024-11-21 11:34 |
2017-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212309
|
7.8 |
HIGH
Local
|
redhat
|
ansible
|
The chroot, jail, and zone connection plugins in ansible before 1.9.2 allow local users to escape a restricted environment via a symlink attack.
|
CWE-59
Link Following
|
CVE-2015-6240
|
2024-11-21 11:34 |
2017-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212310
|
6.1 |
MEDIUM
Network
|
opsview
|
opsview
|
Opsview before 2015-11-06 has XSS via SNMP.
|
CWE-79
Cross-site Scripting
|
CVE-2015-6035
|
2024-11-21 11:34 |
2017-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|