7.5
    High

    CVE-2015-4658

    Last Modified: 6 Nov 2017

    Multiple SQL injection vulnerabilities in admin/login.php in Milw0rm Clone Script 1.0 allow remote attackers to execute arbitrary SQL commands via the (1) usr or (2) pwd parameter.

    Source:walid naceri
    Published:18 Jun 2015
    9.8
    Critical

    CVE-2015-4633

    Last Modified: 26 Jun 2015

    Multiple SQL injection vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow (1) remote attackers to execute arbitrary SQL commands via the number parameter to opac-tags_subject.pl in the OPAC interface or (2) remote authenticated users to execute arbitrary SQL commands via the Filter or (3) Criteria parameter to reports/borrowers_out.pl in the Staff interface.

    Source:Raschin Tavakoli_ Bernhard Garn_ Peter Aufner & Dimitris Simos
    Published:18 Oct 2018
    7.5
    High

    CVE-2015-4632

    Last Modified: 26 Jun 2015

    Multiple directory traversal vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to read arbitrary files via a ..%2f (dot dot encoded slash) in the template_path parameter to (1) svc/virtualshelves/search or (2) svc/members/search.

    Source:Raschin Tavakoli_ Bernhard Garn_ Peter Aufner & Dimitris Simos
    Published:18 Oct 2018
    5.4
    Medium

    CVE-2015-4631

    Last Modified: 31 Aug 2016

    Multiple cross-site scripting (XSS) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to inject arbitrary web script or HTML via the (1) tag parameter to opac-search.pl; the (2) value parameter to authorities/authorities-home.pl; the (3) delay parameter to acqui/lateorders.pl; the (4) authtypecode or (5) tagfield to admin/auth_subfields_structure.pl; the (6) tagfield parameter to admin/marc_subfields_structure.pl; the (7) limit parameter to catalogue/search.pl; the (8) bookseller_filter, (9) callnumber_filter, (10) EAN_filter, (11) ISSN_filter, (12) publisher_filter, or (13) title_filter parameter to serials/serials-search.pl; or the (14) author, (15) collectiontitle, (16) copyrightdate, (17) isbn, (18) manageddate_from, (19) manageddate_to, (20) publishercode, (21) suggesteddate_from, or (22) suggesteddate_to parameter to suggestion/suggestion.pl; or the (23) direction, (24) display or (25) addshelf parameter to opac-shelves.pl.

    Source:Raschin Tavakoli_ Bernhard Garn_ Peter Aufner & Dimitris Simos
    Published:18 Oct 2018
    8
    High

    CVE-2015-4630

    Last Modified: 31 Aug 2016

    Multiple cross-site request forgery (CSRF) vulnerabilities in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, 3.18.x before 3.18.08, and 3.20.x before 3.20.1 allow remote attackers to (1) hijack the authentication of administrators for requests that create a user via a request to members/memberentry.pl or (2) give a user superlibrarian permission via a request to members/member-flags.pl or (3) hijack the authentication of arbitrary users for requests that conduct cross-site scripting (XSS) attacks via the addshelf parameter to opac-shelves.pl.

    Source:Raschin Tavakoli_ Bernhard Garn_ Peter Aufner & Dimitris Simos
    Published:18 Oct 2018
    7.5
    High

    CVE-2015-4624

    Last Modified: 23 Oct 2016

    Hak5 WiFi Pineapple 2.0 through 2.3 uses predictable CSRF tokens.

    Source:Metasploit
    Published:31 Mar 2017
    5
    Medium

    CVE-2015-4616

    Last Modified: 10 Jul 2015

    Directory traversal vulnerability in includes/MapPinImageSave.php in the Easy2Map plugin before 1.2.5 for WordPress allows remote attackers to create arbitrary files via a .. (dot dot) in the map_id parameter.

    Source:Larry W. Cashdollar
    Published:8 Jul 2015
    7.5
    High

    CVE-2015-4614

    Last Modified: 10 Jul 2015

    Multiple SQL injection vulnerabilities in includes/Function.php in the Easy2Map plugin before 1.2.5 for WordPress allow remote attackers to execute arbitrary SQL commands via the mapName parameter in an e2m_img_save_map_name action to wp-admin/admin-ajax.php and other unspecified vectors.

    Source:Larry W. Cashdollar
    Published:8 Jul 2015
    9.8
    Critical

    CVE-2015-4594

    Last Modified: 2 Feb 2016

    eClinicalWorks Population Health (CCMR) suffers from a session fixation vulnerability. When authenticating a user, the application does not assign a new session ID, making it possible to use an existent session ID.

    Source:Jerold Hoong
    Published:10 Jan 2017
    8.8
    High

    CVE-2015-4593

    Last Modified: 2 Feb 2016

    eClinicalWorks Population Health (CCMR) suffers from a cross-site request forgery (CSRF) vulnerability in portalUserService.jsp which allows remote attackers to hijack the authentication of content administrators for requests that could lead to the creation, modification and deletion of users, appointments and employees.

    Source:Jerold Hoong
    Published:10 Jan 2017
    8.8
    High

    CVE-2015-4592

    Last Modified: 2 Feb 2016

    eClinicalWorks Population Health (CCMR) suffers from an SQL injection vulnerability in portalUserService.jsp which allows remote authenticated users to inject arbitrary malicious database commands as part of user input.

    Source:Jerold Hoong
    Published:10 Jan 2017
    6.1
    Medium

    CVE-2015-4591

    Last Modified: 2 Feb 2016

    eClinicalWorks Population Health (CCMR) suffers from a cross site scripting vulnerability in login.jsp which allows remote unauthenticated users to inject arbitrary javascript via the strMessage parameter.

    Source:Jerold Hoong
    Published:10 Jan 2017
    8.8
    High

    CVE-2015-4553

    Last Modified: 5 Jul 2015

    A file upload issue exists in DeDeCMS before 5.7-sp1, which allows malicious users getshell.

    Source:zise
    Published:6 Jan 2020
    9.3
    Critical

    CVE-2015-4523

    Last Modified: 27 Oct 2016

    Blue Coat Malware Analysis Appliance (MAA) before 4.2.5 and Malware Analyzer G2 allow remote attackers to bypass a virtual machine protection mechanism and consequently write to arbitrary files, cause a denial of service (host reboot or reset to factory defaults), or execute arbitrary code via vectors related to saving files during analysis.

    Source:Metasploit
    Published:11 Sept 2017
    8.8
    High

    CVE-2015-4495

    Last Modified: 27 Oct 2016

    The PDF reader in Mozilla Firefox before 39.0.3, Firefox ESR 38.x before 38.1.1, and Firefox OS before 2.2 allows remote attackers to bypass the Same Origin Policy, and read arbitrary files or gain privileges, via vectors involving crafted JavaScript code and a native setter, as exploited in the wild in August 2015.

    Source:Tantaryu MING
    Published:6 Aug 2015
    3.3
    Low

    CVE-2015-4481

    Last Modified: 21 Aug 2015

    Race condition in the Mozilla Maintenance Service in Mozilla Firefox before 40.0 and Firefox ESR 38.x before 38.2 on Windows allows local users to write to arbitrary files and consequently gain privileges via vectors involving a hard link to a log file during an update.

    Source:Google Security Research
    Published:16 Aug 2015
    4.3
    Medium

    CVE-2015-4465

    Last Modified: 4 Jun 2015

    Cross-site scripting (XSS) vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Source:Panagiotis Vagenas
    Published:10 Jun 2015
    6.8
    Medium

    CVE-2015-4460

    Last Modified: 30 Jun 2015

    Cross-site request forgery (CSRF) vulnerability in SecuritySetting/UserSecurity/UserManagement.aspx in B.A.S C2Box before 4.0.0 (r19171) allows remote attackers to hijack the authentication of administrators for requests that add administrator accounts via certain vectors.

    Source:Wissam Bashour
    Published:16 Jul 2015
    9.8
    Critical

    CVE-2015-4455

    Last Modified: 12 Jun 2015

    Unrestricted file upload vulnerability in includes/upload.php in the Aviary Image Editor Add-on For Gravity Forms plugin 3.0 beta for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in wp-content/uploads/gform_aviary.

    Source:Larry W. Cashdollar
    Published:23 May 2017
    10
    Critical

    CVE-2015-4432

    Last Modified: 19 Aug 2015

    Heap-based buffer overflow in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3135 and CVE-2015-5118.

    Source:Google Security Research
    Published:8 Jul 2015
    10
    Critical

    CVE-2015-4430

    Last Modified: 19 Aug 2015

    Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler before 18.0.0.180 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2015-3118, CVE-2015-3124, CVE-2015-3127, CVE-2015-3128, CVE-2015-3129, CVE-2015-3131, CVE-2015-3132, CVE-2015-3136, CVE-2015-3137, CVE-2015-4428, and CVE-2015-5117.

    Source:Google Security Research
    Published:8 Jul 2015
    4.9
    Medium

    CVE-2015-4425

    Last Modified: 14 Jul 2015

    Directory traversal vulnerability in pimcore before build 3473 allows remote authenticated users with the "assets" permission to create or write to arbitrary files via a .. (dot dot) in the dir parameter to admin/asset/add-asset-compatibility.

    Source:Portcullis
    Published:18 Aug 2015
    4.3
    Medium

    CVE-2015-4420

    Last Modified: 12 Jun 2015

    Multiple cross-site scripting (XSS) vulnerabilities in Opsview 4.6.2 and earlier allow remote attackers to inject arbitrary web script or HTML via a (1) crafted check plugin, the (2) description in a host profile, or the (3) plugin_args parameter to a Test service check page.

    Source:Dolev Farhi
    Published:18 Jun 2015
    5
    Medium

    CVE-2015-4414

    Last Modified: 10 Oct 2016

    Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player) plugin 1.1.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

    Source:Larry W. Cashdollar
    Published:17 Jun 2015
    7.5
    High

    CVE-2015-4181

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a .. (dot dot) in the view parameter. NOTE: the provenance of this information is unknown; the details are obtained solely from third party information. NOTE: this vulnerability exists due to an incomplete fix to CVE-2015-4180.

    Source:Amol Naik
    Published:25 Aug 2017
    5
    Medium

    CVE-2015-4153

    Last Modified: 4 Jun 2015

    Directory traversal vulnerability in the zM Ajax Login & Register plugin before 1.1.0 for WordPress allows remote attackers to include and execute arbitrary php files via a relative path in the template parameter in a load_template action to wp-admin/admin-ajax.php.

    Source:Panagiotis Vagenas
    Published:10 Jun 2015
    5
    Medium

    CVE-2015-4148

    Last Modified: 24 Sept 2015

    The do_soap_call function in ext/soap/soap.c in PHP before 5.4.39, 5.5.x before 5.5.23, and 5.6.x before 5.6.7 does not verify that the uri property is a string, which allows remote attackers to obtain sensitive information by providing crafted serialized data with an int data type, related to a "type confusion" issue.

    Source:Filippo Roncari
    Published:3 Mar 2015
    7.5
    High

    CVE-2015-4137

    Last Modified: 6 Nov 2017

    SQL injection vulnerability in related.php in Milw0rm Clone Script 1.0 allows remote attackers to execute arbitrary SQL commands via the program parameter.

    Source:Pancaker
    Published:29 May 2015
    7.5
    High

    CVE-2015-4133

    Last Modified: 21 Apr 2015

    Unrestricted file upload vulnerability in admin/scripts/FileUploader/php.php in the ReFlex Gallery plugin before 3.1.4 for WordPress allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in uploads/ directory.

    Source:Metasploit
    Published:28 May 2015
    4.3
    Medium

    CVE-2015-4127

    Last Modified: 26 May 2015

    Cross-site scripting (XSS) vulnerability in the church_admin plugin before 0.810 for WordPress allows remote attackers to inject arbitrary web script or HTML via the address parameter, as demonstrated by a request to index.php/2015/05/21/church_admin-registration-form/.

    Source:woodspeed
    Published:28 May 2015
    6.8
    Medium

    CVE-2015-4119

    Last Modified: 10 Jun 2015

    Multiple cross-site request forgery (CSRF) vulnerabilities in ISPConfig before 3.0.5.4p7 allow remote attackers to hijack the authentication of (1) administrators for requests that create an administrator account via a request to admin/users_edit.php or (2) arbitrary users for requests that conduct SQL injection attacks via the server parameter to monitor/show_sys_state.php.

    Source:High-Tech Bridge SA
    Published:15 Jun 2015
    6.5
    Medium

    CVE-2015-4118

    Last Modified: 10 Jun 2015

    SQL injection vulnerability in monitor/show_sys_state.php in ISPConfig before 3.0.5.4p7 allows remote authenticated users with monitor permissions to execute arbitrary SQL commands via the server parameter. NOTE: this can be leveraged by remote attackers using CVE-2015-4119.2.

    Source:High-Tech Bridge SA
    Published:15 Jun 2015
    8.8
    High

    CVE-2015-4117

    Last Modified: 24 Jun 2015

    Vesta Control Panel before 0.9.8-14 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the backup parameter to list/backup/index.php.

    Source:High-Tech Bridge SA
    Published:28 Feb 2018
    Low

    CVE-2015-4107

    Last Modified: 1 Sept 2014

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was intended functionality. Notes: none

    Source:Metasploit
    Published:14 Jan 2020
    4.3
    Medium

    CVE-2015-4084

    Last Modified: 27 May 2015

    Cross-site scripting (XSS) vulnerability in the Free Counter plugin 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value_ parameter in a check_stat action to wp-admin/admin-ajax.php.

    Source:Panagiotis Vagenas
    Published:28 May 2015
    2.1
    Low

    CVE-2015-4077

    Last Modified: 8 Aug 2018

    The (1) mdare64_48.sys, (2) mdare32_48.sys, (3) mdare32_52.sys, and (4) mdare64_52.sys drivers in Fortinet FortiClient before 5.2.4 allow local users to read arbitrary kernel memory via a 0x22608C ioctl call.

    Source:sickness & mschenk
    Published:3 Sept 2015
    8.1
    High

    CVE-2015-4075

    Last Modified: 19 Dec 2016

    The Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to write to arbitrary .ini files via a crafted language.save task.

    Source:Simon Rawet
    Published:20 Sept 2017
    7.5
    High

    CVE-2015-4074

    Last Modified: 19 Dec 2016

    Directory traversal vulnerability in the Helpdesk Pro plugin before 1.4.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter in a ticket.download_attachment task.

    Source:Simon Rawet
    Published:20 Sept 2017
    9.8
    Critical

    CVE-2015-4073

    Last Modified: 19 Dec 2016

    Multiple SQL injection vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to execute arbitrary SQL commands via the (1) ticket_code or (2) email parameter or (3) remote authenticated users to execute arbitrary SQL commands via the filter_order parameter.

    Source:Simon Rawet
    Published:20 Sept 2017
    5.4
    Medium

    CVE-2015-4072

    Last Modified: 19 Dec 2016

    Multiple cross-site scripting (XSS) vulnerabilities in the Helpdesk Pro plugin before 1.4.0 for Joomla! allow remote attackers to inject arbitrary web script or HTML via vectors related to name and message.

    Source:Simon Rawet
    Published:20 Sept 2017
    5.3
    Medium

    CVE-2015-4071

    Last Modified: 19 Dec 2016

    The Helpdesk Pro Plugin before 1.4.0 for Joomla! allows remote attackers to read the support tickets of arbitrary users via obtaining the target ticketId, and navigating to http://{target}/component/helpdeskpro/?view=ticket&id={ticketId}.

    Source:Simon Rawet
    Published:18 Aug 2017
    6.5
    Medium

    CVE-2015-4066

    Last Modified: 10 Oct 2016

    Multiple SQL injection vulnerabilities in admin/handlers.php in the GigPress plugin before 2.3.9 for WordPress allow remote authenticated users to execute arbitrary SQL commands via the (1) show_artist_id or (2) show_venue_id parameter in an add action in the gigpress.php page to wp-admin/admin.php.

    Source:Adrián M. F.
    Published:27 May 2015
    3.5
    Low

    CVE-2015-4065

    Last Modified: 10 Oct 2016

    Cross-site scripting (XSS) vulnerability in shared/shortcodes/inbound-shortcodes.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the post parameter to wp-admin/post-new.php.

    Source:Adrián M. F.
    Published:27 May 2015
    6.5
    Medium

    CVE-2015-4064

    Last Modified: 10 Oct 2016

    SQL injection vulnerability in modules/module.ab-testing.php in the Landing Pages plugin before 1.8.5 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the post parameter in an edit delete-variation action to wp-admin/post.php.

    Source:Adrián M. F.
    Published:27 May 2015
    3.5
    Low

    CVE-2015-4063

    Last Modified: 26 May 2015

    Cross-site scripting (XSS) vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to inject arbitrary web script or HTML via the where1 parameter in the nsp_search page to wp-admin/admin.php.

    Source:Adrián M. F.
    Published:27 May 2015
    6.5
    Medium

    CVE-2015-4062

    Last Modified: 26 May 2015

    SQL injection vulnerability in includes/nsp_search.php in the NewStatPress plugin before 0.9.9 for WordPress allows remote authenticated users to execute arbitrary SQL commands via the where1 parameter in the nsp_search page to wp-admin/admin.php.

    Source:Adrián M. F.
    Published:27 May 2015
    4
    Medium

    CVE-2015-4040

    Last Modified: 13 Oct 2015

    Directory traversal vulnerability in the configuration utility in F5 BIG-IP before 12.0.0 and Enterprise Manager 3.0.0 through 3.1.1 allows remote authenticated users to access arbitrary files in the web root via unspecified vectors.

    Source:Karn Ganeshen
    Published:17 Sept 2015
    5.4
    Medium

    CVE-2015-4039

    Last Modified: 21 May 2015

    Multiple cross-site scripting (XSS) vulnerabilities in the WP Membership plugin 1.2.3 for WordPress allow remote authenticated users to inject arbitrary web script or HTML via unspecified (1) profile fields or (2) new post content. NOTE: CVE-2015-4038 can be used to bypass the administrator confirmation step for vector 2.

    Source:Panagiotis Vagenas
    Published:6 Jan 2020
    6.5
    Medium

    CVE-2015-4038

    Last Modified: 21 May 2015

    The WP Membership plugin 1.2.3 for WordPress allows remote authenticated users to gain administrator privileges via an iv_membership_update_user_settings action to wp-admin/admin-ajax.php.

    Source:Panagiotis Vagenas
    Published:3 Jun 2015
    7.2
    High

    CVE-2015-4027

    Last Modified: 2 Dec 2015

    The AcuWVSSchedulerv10 service in Acunetix Web Vulnerability Scanner (WVS) before 10 build 20151125 allows local users to gain privileges via a command parameter in the reporttemplate property in a params JSON object to api/addScan.

    Source:Daniele Linguaglossa
    Published:17 Dec 2015