NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
26028  CVE-2015-4670  Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrary files via a .. (dot dot) in the fileId parameter to AjaxFileUploadHandler.axd.    6.4  Medium  2017-01-19  2015-08-20  View
26027  CVE-2015-4666  Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.3.0 and 2.4.3.0 allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.    Medium  2017-01-19  2015-08-13  View
26026  CVE-2015-4665  Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.3.0 and 2.4.3.0 allows remote attackers to inject arbitrary web script or HTML via the fileName parameter.    4.3  Medium  2017-01-19  2015-08-13  View
26025  CVE-2015-4661  Cross-site scripting (XSS) vulnerability in Symphony CMS 2.6.2 allows remote attackers to inject arbitrary web script or HTML via the sort parameter to system/authors.    4.3  Medium  2017-01-19  2016-11-28  View
26024  CVE-2015-4660  Cross-site scripting (XSS) vulnerability in Enhanced SQL Portal 5.0.7961 allows remote attackers to inject arbitrary web script or HTML via the id parameter to iframe.php.    4.3  Medium  2017-01-19  2016-12-07  View

Page 3152 of 17672, showing 5 records out of 88360 total, starting on record 15756, ending on 15760

Actions