Show filters
275 Total Results
Displaying 201-210 of 275
Sort by:
Attacker Value
Unknown

CVE-2016-5807

Disclosure Date: July 15, 2016 (last updated November 25, 2024)
Tollgrade LightHouse SMS before 5.1 patch 3 allows remote authenticated users to bypass an intended administrative-authentication requirement, and read or change parameter values, via a direct request.
0
Attacker Value
Unknown

CVE-2016-5797

Disclosure Date: July 15, 2016 (last updated November 25, 2024)
Tollgrade LightHouse SMS before 5.1 patch 3 provides different error messages for failed authentication attempts depending on whether the username exists, which allows remote attackers to enumerate account names via a series of attempts.
0
Attacker Value
Unknown

CVE-2016-0864

Disclosure Date: February 13, 2016 (last updated November 25, 2024)
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to obtain sensitive report and username information via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-0863

Disclosure Date: February 13, 2016 (last updated November 25, 2024)
Cross-site request forgery (CSRF) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to hijack the authentication of arbitrary users.
0
Attacker Value
Unknown

CVE-2016-0865

Disclosure Date: February 13, 2016 (last updated November 25, 2024)
Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote authenticated users to change arbitrary passwords via unspecified vectors.
0
Attacker Value
Unknown

CVE-2016-0866

Disclosure Date: February 13, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in Tollgrade SmartGrid LightHouse Sensor Management System (SMS) Software EMS before 5.1, and 4.1.0 Build 16, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-7773

Disclosure Date: November 20, 2015 (last updated October 05, 2023)
Unrestricted file upload vulnerability in the Panel component in Bastian Allgeier Kirby before 2.1.2 allows remote authenticated users to execute arbitrary PHP code by uploading a file that lacks an extension, and then renaming this file to have a .php extension.
0
Attacker Value
Unknown

CVE-2015-5066

Disclosure Date: June 24, 2015 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the MetalGenix GeniXCMS 0.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) content or (2) title field in an add action in the posts page to index.php or the (3) q parameter in the posts page to index.php.
0
Attacker Value
Unknown

CVE-2015-2680

Disclosure Date: March 23, 2015 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in MetalGenix GeniXCMS before 0.0.2 allows remote attackers to hijack the authentication of administrators for requests that add an administrator account via a request in the users page to gxadmin/index.php.
0
Attacker Value
Unknown

CVE-2015-2209

Disclosure Date: March 04, 2015 (last updated October 05, 2023)
DLGuard 4.5 allows remote attackers to obtain the installation path via the c parameter to index.php.
0