CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2015-4308

    Last Modified: 12 Apr 2025

    The webGUI configuration-export feature in Cisco Edge Bluebird Operating System 1.2 on Edge 340 devices allows remote authenticated users to obtain sensitive information via unspecified vectors, aka Bug ID CSCuu43968.

    Published: 19 Aug 2015
    5.5
    Medium

    CVE-2015-4322

    Last Modified: 12 Apr 2025

    Cisco Content Security Management Appliance (SMA) 8.3.6-039, 9.1.0-31, and 9.1.0-103 improperly restricts the privileges available after LDAP authentication, which allows remote authenticated users to read or write to an arbitrary user's Spam Quarantine folder by visiting a spam-notification URL, aka Bug ID CSCuv65894.

    Published: 19 Aug 2015
    5.8
    Medium

    CVE-2015-4297

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in Cisco WebEx Node for Media Convergence Server (MCS) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via crafted HTTP request parameters, aka Bug ID CSCuv32136.

    Published: 19 Aug 2015
    6.4
    Medium

    CVE-2015-4302

    Last Modified: 12 Apr 2025

    The web interface in Cisco FireSIGHT Management Center 5.3.1.4 allows remote attackers to delete arbitrary system policies via modified parameters in a POST request, aka Bug ID CSCuu25390.

    Published: 19 Aug 2015
    8.8
    High

    CVE-2015-2502

    Last Modified: 22 Apr 2026

    Microsoft Internet Explorer 7 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Memory Corruption Vulnerability," as exploited in the wild in August 2015.

    Published: 19 Aug 2015
    6.1
    Medium

    CVE-2015-5216

    Last Modified: 21 Nov 2024

    The Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly escape certain characters in a Python exception-message template, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via an HTTP response.

    Published: 19 Aug 2015
    8.5
    High

    CVE-2015-5222

    Last Modified: 12 Apr 2025

    Red Hat OpenShift Enterprise 3.0.0.0 does not properly check permissions, which allows remote authenticated users with build permissions to execute arbitrary shell commands with root permissions on arbitrary build pods via unspecified vectors.

    Published: 19 Aug 2015
    6.1
    Medium

    CVE-2015-5215

    Last Modified: 21 Nov 2024

    The default configuration of the Jinja templating engine used in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not enable auto-escaping, which makes it easier for remote attackers to conduct cross-site scripting (XSS) attacks via template variables. NOTE: This may be a duplicate of CVE-2015-5216. Moreover, the Jinja development team does not enable auto-escape by default for performance issues as explained in https://jinja.palletsprojects.com/en/master/faq/#why-is-autoescaping-not-the-default.

    Published: 19 Aug 2015
    4
    Medium

    CVE-2015-5217

    Last Modified: 12 Apr 2025

    providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 before 1.0.1 does not properly check permissions to update the SAML2 Service Provider (SP) owner, which allows remote authenticated users to cause a denial of service via a duplicate SP name.

    Published: 19 Aug 2015
    6.3
    Medium

    CVE-2015-6918

    Last Modified: 20 Apr 2025

    salt before 2015.5.5 leaks git usernames and passwords to the log.

    Published: 19 Aug 2015
    4.3
    Medium

    CVE-2015-5481

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.

    Published: 18 Aug 2015
    4
    Medium

    CVE-2015-5482

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.

    Published: 18 Aug 2015
    4.3
    Medium

    CVE-2015-5487

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Camtasia Relay module 6.x-2.x before 6.x-3.2 and 7.x-2.x before 7.x-1.3 for Drupal allows remote authenticated users with the "view meta information" permission to inject arbitrary web script or HTML via unspecified vectors related to the meta access tab.

    Published: 18 Aug 2015
    2.1
    Low

    CVE-2015-5488

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the MailChimp Signup submodule in the MailChimp module 7.x-3.x before 7.x-3.3 for Drupal allows remote authenticated users with the "administer mailchimp" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Aug 2015
    3.5
    Low

    CVE-2015-5489

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Smart Trim module 7.x-1.x before 7.x-1.5 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via vectors involving the field settings form.

    Published: 18 Aug 2015
    5
    Medium

    CVE-2015-5490

    Last Modified: 12 Apr 2025

    The _views_fetch_data method in includes/cache.inc in the Views module 7.x-3.5 through 7.x-3.10 for Drupal does not rebuild the full cache if the static cache is not empty, which allows remote attackers to bypass intended filters and obtain access to hidden content via unspecified vectors.

    Published: 18 Aug 2015
    3.5
    Low

    CVE-2015-5491

    Last Modified: 12 Apr 2025

    The Dynamic display block module 7.x-1.x before 7.x-1.1 for Drupal allows remote authenticated users to bypass intended access restrictions and read sensitive titles by leveraging the "administer ddblock" permission.

    Published: 18 Aug 2015
    4.3
    Medium

    CVE-2015-5492

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Video Consultation module for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Aug 2015
    3.5
    Low

    CVE-2015-5494

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Webform Matrix Component module 7.x-4.x before 7.x-4.13 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Aug 2015
    2.1
    Low

    CVE-2015-5495

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Mobile sliding menu module 7.x-2.x before 7.x-2.1 for Drupal allows remote authenticated users with the "administer menu" permission to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Aug 2015
    5
    Medium

    CVE-2015-5496

    Last Modified: 12 Apr 2025

    The pass2pdf module for Drupal does not restrict access to generated PDF files, which allows remote attackers to obtain user passwords via unspecified vectors.

    Published: 18 Aug 2015
    3.5
    Low

    CVE-2015-5497

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Web Links module 6.x-2.x before 6.x-2.6 and 7.x-1.x before 7.x-1.0 for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Aug 2015
    5
    Medium

    CVE-2015-5498

    Last Modified: 12 Apr 2025

    The Shipwire API module 7.x-1.x before 7.x-1.03 for Drupal does not check the view permission for the shipments overview (admin/shipwire/shipments), which allows remote attackers to obtain sensitive information via a request to the page.

    Published: 18 Aug 2015
    4
    Medium

    CVE-2015-5499

    Last Modified: 12 Apr 2025

    The Navigate module for Drupal does not properly check permissions, which allows remote authenticated users to modify custom widgets and create widget database records by leveraging the "navigate view" permission.

    Published: 18 Aug 2015
    3.5
    Low

    CVE-2015-5500

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Navigate module for Drupal allows remote authenticated users with certain permissions to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Aug 2015
    7.5
    High

    CVE-2015-5501

    Last Modified: 12 Apr 2025

    The Hostmaster (Aegir) module 6.x-2.x before 6.x-2.4 and 7.x-3.x before 7.x-3.0-beta2 for Drupal allows remote attackers to execute arbitrary PHP code via a crafted file in the directory used to write Apache vhost files for hosted sites in a multi-site environment.

    Published: 18 Aug 2015
    7.5
    High

    CVE-2015-5502

    Last Modified: 12 Apr 2025

    The Storage API module 7.x-1.x before 7.x-1.8 for Drupal does not properly restrict access to Storage API fields attached to entities that are not nodes, which allows remote attackers to have unspecified impact via unknown vectors.

    Published: 18 Aug 2015
    5.8
    Medium

    CVE-2015-5503

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Chamilo integration module 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified parameters.

    Published: 18 Aug 2015
    7.5
    High

    CVE-2015-5504

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the Novalnet Payment Module Ubercart module for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 18 Aug 2015
    6.8
    Medium

    CVE-2015-5505

    Last Modified: 12 Apr 2025

    The HTTP Strict Transport Security (HSTS) module 6.x-1.x before 6.x-1.1 and 7.x-1.x before 7.x-1.2 for Drupal does not properly implement the "include subdomains" directive, which causes the HSTS policy to not be applied to subdomains and allows man-in-the-middle attackers to have unspecified impact via unknown vectors.

    Published: 18 Aug 2015
    5
    Medium

    CVE-2015-5506

    Last Modified: 12 Apr 2025

    The Apache Solr Real-Time module 7.x-1.x before 7.x-1.2 for Drupal does not check the status of an entity when indexing, which allows remote attackers to obtain information about unpublished content via a search.

    Published: 18 Aug 2015
    4.3
    Medium

    CVE-2015-5507

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Inline Entity Form module 7.x-1.x before 7.x-1.6 for Drupal allows remote authenticated users with permission to create or edit fields to inject arbitrary web script or HTML via unspecified vectors.

    Published: 18 Aug 2015
    5.1
    Medium

    CVE-2015-5508

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in the XC NCIP Provider module in the eXtensible Catalog (XC) Drupal Toolkit allows remote attackers to hijack the authentication of users with the "administer ncip providers" permission for requests that alter NCIP providers via a crafted request.

    Published: 18 Aug 2015
    6
    Medium

    CVE-2015-5509

    Last Modified: 12 Apr 2025

    The Administration Views module 7.x-1.x before 7.x-1.4 for Drupal, when used with other unspecified modules, does not properly grant access to administration pages, which allows remote administrators to bypass intended restrictions via unspecified vectors.

    Published: 18 Aug 2015
    5.8
    Medium

    CVE-2015-5510

    Last Modified: 12 Apr 2025

    Open redirect vulnerability in the Content Construction Kit (CCK) 6.x-2.x before 6.x-2.10 for Drupal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the destinations parameter, related to administration pages.

    Published: 18 Aug 2015
    5
    Medium

    CVE-2015-5511

    Last Modified: 12 Apr 2025

    The HybridAuth Social Login module 7.x-2.x before 7.x-2.13 for Drupal allows remote attackers to bypass the user registration by administrator only configuration and create an account via a social login.

    Published: 18 Aug 2015
    5
    Medium

    CVE-2015-5512

    Last Modified: 12 Apr 2025

    The me aliases module 6.x-2.x before 6.x-2.10 and 7.x-1.x before 7.x-1.2 for Drupal allows remote attackers to access Views using the "me" user argument handler by substituting "me" for a user id in a URL.

    Published: 18 Aug 2015
    2.1
    Low

    CVE-2015-5513

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Shibboleth authentication module 6.x-4.x before 6.x-4.2 and 7.x-4.x before 7.x-4.2 for Drupal allows remote authenticated users with the "Administer blocks" permission to inject arbitrary web script or HTML via unspecified vectors related to a login link.

    Published: 18 Aug 2015
    2.6
    Low

    CVE-2015-5514

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Migrate module 7.x-2.x before 7.x-2.8 for Drupal, when the migrate_ui submodule is enabled, allows user-assisted remote attackers to inject arbitrary web script or HTML via a destination field label.

    Published: 18 Aug 2015
    4.9
    Medium

    CVE-2015-5515

    Last Modified: 12 Apr 2025

    The Views Bulk Operations (VBO) module 6.x-1.x and 7.x-3.x before 7.x-3.3 for Drupal, when the bulk operation for changing Roles is enabled, allows remote authenticated users to edit user accounts and add arbitrary roles to the accounts by leveraging access to a user account listing view with VBO enabled.

    Published: 18 Aug 2015
    4.9
    Medium

    CVE-2015-4425

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permission to create or write to arbitrary files via a .. (dot dot) in the dir parameter to admin/asset/add-asset-compatibility.

    Published: 18 Aug 2015
    7.5
    High

    CVE-2015-4426

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in pimcore before build 3473 allows remote attackers to execute arbitrary SQL commands via the filter parameter to admin/asset/grid-proxy.

    Published: 18 Aug 2015
    6.4
    Medium

    CVE-2015-4670

    Last Modified: 12 Apr 2025

    Directory traversal vulnerability in the AjaxFileUpload control in DevExpress AJAX Control Toolkit (aka AjaxControlToolkit) before 15.1 allows remote attackers to write to arbitrary files via a .. (dot dot) in the fileId parameter to AjaxFileUploadHandler.axd.

    Published: 18 Aug 2015
    5
    Medium

    CVE-2015-5493

    Last Modified: 12 Apr 2025

    The Entityform Block module 7.x-1.x before 7.x-1.3 for Drupal does not properly check permissions when a form is locked to a role, which allows remote attackers to obtain access to certain entityforms via unspecified vectors.

    Published: 18 Aug 2015
    6.8
    Medium

    CVE-2015-6517

    Last Modified: 12 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in phpLiteAdmin 1.1 allows remote attackers to hijack the authentication of users for requests that drop database tables via the droptable parameter to phpliteadmin.php.

    Published: 18 Aug 2015
    4.3
    Medium

    CVE-2015-6518

    Last Modified: 12 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in phpLiteAdmin 1.1 allow remote attackers to inject arbitrary web script or HTML via the (1) PATH_INFO, (2) droptable parameter, or (3) table parameter to phpliteadmin.php.

    Published: 18 Aug 2015
    7.5
    High

    CVE-2015-6519

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in Arab Portal 3 allows remote attackers to execute arbitrary SQL commands via the showemail parameter in a signup action to members.php.

    Published: 18 Aug 2015
    7.5
    High

    CVE-2015-5599

    Last Modified: 12 Apr 2025

    Multiple SQL injection vulnerabilities in upload.php in the Powerplay Gallery plugin 3.3 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) albumid or (2) name parameter.

    Published: 18 Aug 2015
    5
    Medium

    CVE-2015-6512

    Last Modified: 12 Apr 2025

    SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute arbitrary SQL commands via the time parameter to server/freichat.php.

    Published: 18 Aug 2015
    4.3
    Medium

    CVE-2015-5485

    Last Modified: 12 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Event Import page (import-eventbrite-events.php) in the Modern Tribe Eventbrite Tickets plugin before 3.10.2 for WordPress allows remote attackers to inject arbitrary web script or HTML via the "error" parameter to wp-admin/edit.php.

    Published: 18 Aug 2015