NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
85245 | CVE-2015-7563 | Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-20 | View | |
85244 | CVE-2015-7562 | Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) label value of an item or (2) name of a role. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-20 | View | |
85243 | CVE-2015-6674 | Buffer underflow vulnerability in the Debian inspircd package before 2.0.5-1+deb7u1 for wheezy and before 2.0.16-1 for jessie and sid. NOTE: This issue exists as an additional issue from an incomplete fix of CVE-2012-1836. | 2 | 7.5 | High | 2017-04-27 | 2017-04-20 | View | |
85242 | CVE-2015-6568 | Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" after originally using the parameter "filename" for uploading a JPEG image. Exploitation requires a registered user who has access to upload functionality. | 2 | 6.5 | Medium | 2017-04-27 | 2017-04-21 | View | |
85241 | CVE-2015-6567 | Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exploitation requires a registered user who has access to upload functionality. | 2 | 6.5 | Medium | 2017-04-27 | 2017-04-21 | View |
Page 624 of 17672, showing 5 records out of 88360 total, starting on record 3116, ending on 3120