CVE Database - 2015

Browse known vulnerabilities with WAF coverage analysis. See which CVEs are detectable by Web Application Firewalls and their OWASP CRS rules.

1874
Matching CVEs
16133
Critical
35026
High
84348
High WAF Coverage

CVE-2015-7297

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in Joomla! 3.2 before 3.4.4 allows remote attackers to execute arbitrary SQL commands via unspecified vectors, a different vulnerability than CVE-2015-7858.

SQL Injection
WAF: High

CVE-2015-5670

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2015-5668

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in Techno Project Japan Enisys Gw before 1.4.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

SQL Injection
WAF: High

CVE-2015-7903

MEDIUM
6.50 CVSS 2.0

SQL injection vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

SQL Injection
WAF: High

CVE-2015-7901

MEDIUM
6.50 CVSS 2.0

Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.

OS Command Injection
WAF: High

CVE-2015-6494

LOW
3.50 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x before 2.6.0 build 430 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2015-6493

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in Infinite Automation Mango Automation 2.5.x and 2.6.x through 2.6.0 build 430 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2015-6488

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the web server on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2015-6486

MEDIUM
6.50 CVSS 2.0

SQL injection vulnerability on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.

SQL Injection
WAF: High

CVE-2015-3970

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in the web interface on Janitza UMG 508, 509, 511, 604, and 605 devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2015-3967

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability on Janitza UMG 508, 509, 511, 604, and 605 devices allows remote attackers to hijack the authentication of arbitrary users.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2015-5188

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in the Web Console (web-console) in Red Hat Enterprise Application Platform before 6.4.4 and WildFly (formerly JBoss Application Server) before 2.0.0.CR9 allows remote attackers to hijack the authentication of administrators for requests that make arbitrary changes to an instance via vectors involving a file upload using a multipart/form-data submission.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2015-5665

MEDIUM
5.10 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in LOCKON EC-CUBE 2.11.0 through 2.13.3 allows remote attackers to hijack the authentication of arbitrary users for requests that write to PHP scripts, related to the doValidToken function.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2015-7699

HIGH
9.00 CVSS 2.0

The files_external app in ownCloud Server before 7.0.9, 8.0.x before 8.0.7, and 8.1.x before 8.1.2 allows remote authenticated users to instantiate arbitrary classes and possibly execute arbitrary code via a crafted mount point option, related to "objectstore."

Improper Input Validation
WAF: Medium

CVE-2015-6500

HIGH
7.50 CVSS 2.0

Directory traversal vulnerability in ownCloud Server before 8.0.6 and 8.1.x before 8.1.1 allows remote authenticated users to list directory contents and possibly cause a denial of service (CPU consumption) via a .. (dot dot) in the dir parameter to index.php/apps/files/ajax/scan.php.

Path Traversal
WAF: High

CVE-2015-5014

HIGH
9.30 CVSS 2.0

IBM Cognos Disclosure Management (CDM) 10.1.x and 10.2.x before 10.2.4 IF10 allows man-in-the-middle attackers to obtain access by spoofing an executable file during a client upload operation.

Improper Input Validation
WAF: Medium

CVE-2015-5011

LOW
3.20 CVSS 2.0

IBM WebSphere Message Broker 8 before 8.0.0.6 and Integration Bus 9 before 9.0.0.4 do not check authorization for MQSISTARTMSGFLOW and MQSISTOPMSGFLOW commands, which allows local users to bypass intended access restrictions, and start or stop a service, by issuing a command.

Command Injection
WAF: High

CVE-2015-4974

HIGH
7.20 CVSS 2.0

IBM General Parallel File System (GPFS) 3.5.x before 3.5.0.27 and 4.1.x before 4.1.1.2 and Spectrum Scale 4.1.1.x before 4.1.1.2 allow local users to obtain root privileges for command execution via unspecified vectors.

Command Injection
WAF: High

CVE-2015-1003

MEDIUM
5.00 CVSS 2.0

Directory traversal vulnerability in IniNet embeddedWebServer (aka eWebServer) before 2.02 allows remote attackers to read arbitrary files via a crafted pathname.

Path Traversal
WAF: High

CVE-2015-7006

MEDIUM
6.80 CVSS 2.0

Directory traversal vulnerability in the BOM (aka Bill of Materials) component in Apple iOS before 9.1, OS X before 10.11.1, and watchOS before 2.0.1 allows remote attackers to execute arbitrary code via a crafted CPIO archive.

Path Traversal
WAF: High

CVE-2015-6987

LOW
2.10 CVSS 2.0

The File Bookmark component in Apple OS X before 10.11.1 allows local users to cause a denial of service (application crash) via crafted bookmark metadata in a folder.

Improper Input Validation
WAF: Medium

CVE-2015-5945

HIGH
7.20 CVSS 2.0

The Sandbox subsystem in Apple OS X before 10.11.1 allows local users to gain privileges via vectors involving NVRAM parameters.

Improper Input Validation
WAF: Medium

CVE-2015-7004

HIGH
7.10 CVSS 2.0

The kernel in Apple iOS before 9.1 allows attackers to cause a denial of service via a crafted app.

Improper Input Validation
WAF: Medium

CVE-2015-7698

HIGH
9.00 CVSS 2.0

icewind1991 SMB before 1.0.3 allows remote authenticated users to execute arbitrary SMB commands via shell metacharacters in the user argument in the (1) listShares function in Server.php or the (2) connect or (3) read function in Share.php.

OS Command Injection
WAF: High

CVE-2015-7299

HIGH
7.50 CVSS 2.0

SQL injection vulnerability in Runtime/Runtime/AjaxCall.ashx in K2 blackpearl, smartforms, and K2 for SharePoint 4.6.7 allows remote attackers to execute arbitrary SQL commands via the xml parameter.

SQL Injection
WAF: High

CVE-2015-4718

HIGH
9.00 CVSS 2.0

The external SMB storage driver in ownCloud Server before 6.0.8, 7.0.x before 7.0.6, and 8.0.x before 8.0.4 allows remote authenticated users to execute arbitrary SMB commands via a ; (semicolon) character in a file.

OS Command Injection
WAF: High

CVE-2015-4716

HIGH
10.00 CVSS 2.0

Directory traversal vulnerability in the routing component in ownCloud Server before 7.0.6 and 8.0.x before 8.0.4, when running on Windows, allows remote attackers to reinstall the application or execute arbitrary code via unspecified vectors.

Path Traversal
WAF: High

CVE-2015-7822

MEDIUM
5.00 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in Kentico CMS 8.2 allow remote attackers to inject arbitrary web script or HTML via a (1) parameter name to CMSModules/AdminControls/Pages/UIPage.aspx or the (2) CMSBodyClass cookie variable to the default URI.

Cross-Site Scripting (XSS)
WAF: High

CVE-2015-5953

LOW
3.50 CVSS 2.0

Cross-site scripting (XSS) vulnerability in the activity application in ownCloud Server before 7.0.5 and 8.0.x before 8.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a " (double quote) character in a filename in a shared folder.

Cross-Site Scripting (XSS)
WAF: High

CVE-2015-7876

HIGH
7.50 CVSS 2.0

The escapeLike function in sqlsrv/database.inc in the Drupal 7 driver for SQL Server and SQL Azure 7.x-1.x before 7.x-1.4 does not properly escape certain characters, which allows remote attackers to execute arbitrary SQL commands via vectors involving a module using the db_like function.

SQL Injection
WAF: High

CVE-2015-7750

MEDIUM
5.00 CVSS 2.0

The L2TP packet processing functionality in Juniper Netscreen and ScreenOS Firewall products with ScreenOS before 6.3.0r13-dnd1, 6.3.0r14 through 6.3.0r18 before 6.3.0r18-dnc1, and 6.3.0r19 allows remote attackers to cause a denial of service via a crafted L2TP packet.

Improper Input Validation
WAF: Medium

CVE-2015-7749

HIGH
7.80 CVSS 2.0

The PFE daemon in Juniper vSRX virtual firewalls with Junos OS before 15.1X49-D20 allows remote attackers to cause a denial of service via an unspecified connection request to the "host-OS."

Improper Input Validation
WAF: Medium

CVE-2015-7748

MEDIUM
5.00 CVSS 2.0

Juniper chassis with Trio (Trinity) chipset line cards and Junos OS 13.3 before 13.3R8, 14.1 before 14.1R6, 14.2 before 14.2R5, and 15.1 before 15.1R2 allow remote attackers to cause a denial of service (MPC line card crash) via a crafted uBFD packet.

Improper Input Validation
WAF: Medium

CVE-2015-6477

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2015-6844

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Reviewer in EMC SourceOne Email Supervisor before 7.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2015-5662

MEDIUM
6.40 CVSS 2.0

Directory traversal vulnerability in Avast before 150918-0 allows remote attackers to delete or write to arbitrary files via a crafted entry in a ZIP archive.

Path Traversal
WAF: High

CVE-2015-5444

MEDIUM
4.30 CVSS 2.0

Multiple cross-site scripting (XSS) vulnerabilities in HP Smart Profile Server Data Analytics Layer (SPS DAL) 2.3 before 2.3.5 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.

Cross-Site Scripting (XSS)
WAF: High

CVE-2015-7683

MEDIUM
4.00 CVSS 2.0

Absolute path traversal vulnerability in Font.php in the Font plugin before 7.5.1 for WordPress allows remote administrators to read arbitrary files via a full pathname in the url parameter to AjaxProxy.php.

Path Traversal
WAF: High

CVE-2015-7682

MEDIUM
6.50 CVSS 2.0

Multiple SQL injection vulnerabilities in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allow remote administrators to execute arbitrary SQL commands via the (1) select_invitaion_code_bulk_option or (2) invi_del_id parameter in the pie-invitation-codes page to wp-admin/admin.php.

SQL Injection
WAF: High

CVE-2015-7377

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in pie-register/pie-register.php in the Pie Register plugin before 2.0.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the invitaion_code parameter in a pie-register page to the default URI.

Cross-Site Scripting (XSS)
WAF: High

CVE-2015-1813

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1812.

Cross-Site Scripting (XSS)
WAF: High

CVE-2015-1812

MEDIUM
4.30 CVSS 2.0

Cross-site scripting (XSS) vulnerability in Jenkins before 1.606 and LTS before 1.596.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, a different vulnerability than CVE-2015-1813.

Cross-Site Scripting (XSS)
WAF: High

CVE-2015-1808

LOW
3.50 CVSS 2.0

Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users to cause a denial of service (improper plug-in and tool installation) via crafted update center data.

Improper Input Validation
WAF: Medium

CVE-2015-1807

LOW
3.50 CVSS 2.0

Directory traversal vulnerability in Jenkins before 1.600 and LTS before 1.596.1 allows remote authenticated users with certain permissions to read arbitrary files via a symlink, related to building artifacts.

Path Traversal
WAF: High

CVE-2015-6334

MEDIUM
5.00 CVSS 2.0

Cisco ASR 5000 and 5500 devices with software 18.0.0.57828 and 19.0.M0.61045 allow remote attackers to cause a denial of service (vpnmgr process restart) via a crafted header in a TACACS packet, aka Bug ID CSCuw01984.

Improper Input Validation
WAF: Medium

CVE-2015-6003

HIGH
9.30 CVSS 2.0

Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

Path Traversal
WAF: High

CVE-2015-5660

MEDIUM
6.80 CVSS 2.0

Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

Cross-Site Request Forgery (CSRF)
WAF: Low

CVE-2015-7839

HIGH
7.50 CVSS 2.0

SolarWinds Log and Event Manager (LEM) allows remote attackers to execute arbitrary commands on managed computers via a request to services/messagebroker/nonsecurestreamingamf involving the traceroute functionality.

Command Injection
WAF: High

CVE-2015-7838

HIGH
10.00 CVSS 2.0

ProcessFileUpload.jsp in SolarWinds Storage Manager before 6.2 allows remote attackers to upload and execute arbitrary files via unspecified vectors.

Improper Input Validation
WAF: Medium

CVE-2015-7729

MEDIUM
6.50 CVSS 2.0

Eval injection in test-net.xsjs in the Web-based Development Workbench in SAP HANA Developer Edition DB 1.00.091.00.1418659308 allows remote authenticated users to execute arbitrary XSJS code via unspecified vectors, aka SAP Security Note 2153892.

Code Injection
WAF: Medium
Page 5 of 38 (1874 CVEs)