Total
3678 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2015-8351 | 1 Gwolle Guestbook Project | 1 Gwolle Guestbook | 2024-11-21 | 6.8 MEDIUM | 9.0 CRITICAL |
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences regardless of whether allow_url_include is enabled. | |||||
CVE-2015-7905 | 1 Unitronics | 1 Visilogic Oplc Ide | 2024-11-21 | 7.5 HIGH | N/A |
Unitronics VisiLogic OPLC IDE before 9.8.02 allows remote attackers to execute unspecified code via unknown vectors. | |||||
CVE-2015-7729 | 1 Sap | 1 Hana | 2024-11-21 | 6.5 MEDIUM | N/A |
Eval injection in test-net.xsjs in the Web-based Development Workbench in SAP HANA Developer Edition DB 1.00.091.00.1418659308 allows remote authenticated users to execute arbitrary XSJS code via unspecified vectors, aka SAP Security Note 2153892. | |||||
CVE-2015-7381 | 1 Refbase | 1 Refbase | 2024-11-21 | 7.5 HIGH | N/A |
Multiple PHP remote file inclusion vulnerabilities in install.php in Web Reference Database (aka refbase) through 0.9.6 allow remote attackers to execute arbitrary PHP code via the (1) pathToMYSQL or (2) databaseStructureFile parameter, a different issue than CVE-2015-6008. | |||||
CVE-2015-6576 | 1 Atlassian | 1 Bamboo | 2024-11-21 | 6.5 MEDIUM | 8.8 HIGH |
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource. | |||||
CVE-2015-6555 | 1 Symantec | 1 Endpoint Protection Manager | 2024-11-21 | 8.5 HIGH | N/A |
Symantec Endpoint Protection Manager (SEPM) 12.1 before 12.1-RU6-MP3 allows remote attackers to execute arbitrary Java code by connecting to the console Java port. | |||||
CVE-2015-6531 | 1 Paloaltonetworks | 1 Pan-os | 2024-11-21 | 9.3 HIGH | 7.8 HIGH |
Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file. | |||||
CVE-2015-5970 | 1 Novell | 1 Zenworks Configuration Management | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference. | |||||
CVE-2015-5721 | 1 Misp-project | 1 Malware Information Sharing Platform | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp. | |||||
CVE-2015-5693 | 1 Symantec | 1 Web Gateway | 2024-11-21 | 7.9 HIGH | N/A |
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands via vectors related to "traffic capture." | |||||
CVE-2015-5687 | 1 Anchorcms | 1 Anchor Cms | 2024-11-21 | 7.5 HIGH | N/A |
system/session/drivers/cookie.php in Anchor CMS 0.9.x allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in a cookie. | |||||
CVE-2015-5647 | 1 Cybozu | 1 Garoon | 2024-11-21 | 8.5 HIGH | N/A |
The RSS Reader component in Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via unspecified vectors, aka CyVDB-866. | |||||
CVE-2015-5646 | 1 Cybozu | 1 Garoon | 2024-11-21 | 8.5 HIGH | N/A |
Cybozu Garoon 3.x through 3.7.5 and 4.x through 4.0.3 allows remote authenticated users to execute arbitrary PHP code via unspecified vectors, aka CyVDB-863 and CyVDB-867. | |||||
CVE-2015-5644 | 1 Icz | 1 Matchasns | 2024-11-21 | 6.8 MEDIUM | N/A |
The installer in ICZ MATCHA SNS before 1.3.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors. | |||||
CVE-2015-5643 | 1 Icz | 1 Matchasns | 2024-11-21 | 6.8 MEDIUM | N/A |
The installer in ICZ MATCHA INVOICE before 2.5.7 does not properly configure the database, which allows remote attackers to execute arbitrary PHP code via unspecified vectors. | |||||
CVE-2015-5603 | 1 Atlassian | 1 Hipchat | 2024-11-21 | 6.5 MEDIUM | N/A |
The HipChat for JIRA plugin before 6.30.0 for Atlassian JIRA allows remote authenticated users to execute arbitrary Java code via unspecified vectors, related to "Velocity Template Injection Vulnerability." | |||||
CVE-2015-5243 | 1 Phpwhois Project | 1 Phpwhois | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
phpWhois allows remote attackers to execute arbitrary code via a crafted whois record. | |||||
CVE-2015-5242 | 1 Redhat | 1 Gluster Storage | 2024-11-21 | 6.0 MEDIUM | N/A |
OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a crafted extended attribute (xattrs). | |||||
CVE-2015-4726 | 1 Audiosharescript | 1 Audioshare | 2024-11-21 | 7.5 HIGH | N/A |
PHP remote file inclusion vulnerability in ajax/myajaxphp.php in AudioShare 2.0.2 allows remote attackers to execute arbitrary PHP code via a URL in the config['basedir'] parameter. | |||||
CVE-2015-4338 | 1 Xcloner | 1 Xcloner | 2024-11-21 | 6.5 MEDIUM | N/A |
Static code injection vulnerability in the XCloner plugin 3.1.2 for WordPress allows remote authenticated users to inject arbitrary PHP code into the language files via a Translation LM_FRONT_* field for a language, as demonstrated by language/italian.php. |