|
211891
|
9.8 |
CRITICAL
Network
|
rxtec
|
rxadmin
|
Multiple SQL injection vulnerabilities in the login page in RXTEC RXAdmin UPDATE 06 / 2012 allow remote attackers to execute arbitrary SQL commands via the (1) loginpassword, (2) loginusername, (3) z…
|
CWE-89
SQL Injection
|
CVE-2015-8298
|
2024-11-21 11:38 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211892
|
6.1 |
MEDIUM
Network
|
cloudera
|
hue
|
Open redirect vulnerability in Cloudera HUE before 3.10.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the next parameter.
|
CWE-601
Open Redirect
|
CVE-2015-8094
|
2024-11-21 11:38 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211893
|
6.5 |
MEDIUM
Network
|
puppet
|
puppet_enterprise
|
The console in Puppet Enterprise 3.7.x, 3.8.x, and 2015.2.x does not set the secure flag for the JSESSIONID cookie in an HTTPS session, which makes it easier for remote attackers to capture this cook…
|
CWE-200
Information Exposure
|
CVE-2015-8470
|
2024-11-21 11:38 |
2017-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211894
|
7.0 |
HIGH
Local
|
sudo_project
|
sudo
|
The SHA-2 digest support in the sudoers plugin in sudo after 1.8.7 allows local users with write permissions to parts of the called command to replace them before it is executed.
|
CWE-362
Race Condition
|
CVE-2015-8239
|
2024-11-21 11:38 |
2017-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211895
|
9.8 |
CRITICAL
Network
|
manageengine
|
desktop_central
|
The FileUploadServlet class in ManageEngine Desktop Central 9 before build 91093 allows remote attackers to upload and execute arbitrary files via the ConnectionId parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2015-8249
|
2024-11-21 11:38 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211896
|
9.8 |
CRITICAL
Network
|
magento
|
magento
|
Password reset tokens in Magento CE before 1.9.2.2, and Magento EE before 1.14.2.2 are passed via a GET request and not canceled after use, which allows remote attackers to obtain user passwords via …
|
CWE-200
Information Exposure
|
CVE-2015-8707
|
2024-11-21 11:38 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211897
|
5.4 |
MEDIUM
Network
|
php-fusion
|
php-fusion
|
Cross-site scripting (XSS) vulnerability in PHP-Fusion 9.
|
CWE-79
Cross-site Scripting
|
CVE-2015-8375
|
2024-11-21 11:38 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211898
|
5.9 |
MEDIUM
Network
|
unify
|
openstage_60_firmware openscape_desk_phone_ip_55g_sip_firmware openstage_15_firmware openstage_20e_firmware openstage_20_firmware openstage_40_firmware openscape_desk_phone_ip_35g_s…
|
OpenStage 60 and OpenScape Desk Phone IP 55G SIP V3, OpenStage 15, 20E, 20 and 40 and OpenScape Desk Phone IP 35G SIP V3, OpenScape Desk Phone IP 35G Eco SIP V3, OpenStage 60 and OpenScape Desk Phone…
|
CWE-200
Information Exposure
|
CVE-2015-8251
|
2024-11-21 11:38 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211899
|
7.5 |
HIGH
Network
|
chef
|
chef
|
The knife bootstrap command in chef Infra client before version 15.4.45 leaks the validator.pem private RSA key to /var/log/messages.
|
CWE-200
Information Exposure
|
CVE-2015-8559
|
2024-11-21 11:38 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211900
|
3.7 |
LOW
Network
|
huawei
|
p8_firmware
|
Huawei P8 before GRA-CL00C92B210, before GRA-L09C432B200, before GRA-TL00C01B210, and before GRA-UL00C00B210 allows remote attackers to obtain user equipment (aka UE) measurements of signal strengths.
|
CWE-200
Information Exposure
|
CVE-2015-8224
|
2024-11-21 11:38 |
2017-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|