Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2016-02-12 CVE-2016-1323 Information Exposure vulnerability in Cisco Spark 201506Base
The REST interface in Cisco Spark 2015-06 allows remote authenticated users to obtain sensitive information via a request for an unspecified file, aka Bug ID CSCuv84048.
network
low complexity
cisco CWE-200
4.3
2016-02-12 CVE-2016-1320 OS Command Injection vulnerability in Cisco Prime Collaboration 11.0.0/9.0.0/9.0.5
The CLI in Cisco Prime Collaboration 9.0 and 11.0 allows local users to execute arbitrary OS commands as root by leveraging administrator privileges, aka Bug ID CSCux69286.
local
low complexity
cisco CWE-78
6.7
2016-02-12 CVE-2016-0882 Unspecified vulnerability in EMC Documentum XCP 2.1/2.2
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to read arbitrary files via a POST request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue.
network
low complexity
emc
5.4
2016-02-12 CVE-2016-0881 Injection vulnerability in EMC Documentum XCP 2.1/2.2
EMC Documentum xCP 2.1 before patch 23 and 2.2 before patch 11 allows remote authenticated users to conduct Documentum Query Language (DQL) injection attacks and obtain sensitive repository information by appending a query to a REST request.
network
low complexity
emc CWE-74
6.5
2016-02-10 CVE-2016-0955 Cross-site Scripting vulnerability in Adobe Experience Manager 6.1.0
Cross-site scripting (XSS) vulnerability in Adobe Experience Manager (AEM) 6.1.0 allows remote authenticated users to inject arbitrary web script or HTML via a folder title field that is mishandled in the Deletion popup dialog.
network
low complexity
adobe CWE-79
6.1
2016-02-10 CVE-2016-0950 7PK - Security Features vulnerability in Adobe Connect
Adobe Connect before 9.5.2 allows remote attackers to spoof the user interface via unspecified vectors.
network
low complexity
adobe CWE-254
5.3
2016-02-10 CVE-2015-7680 Information Exposure vulnerability in Ipswitch Moveit DMZ 8.1
Ipswitch MOVEit DMZ before 8.2 provides different error messages for authentication attempts depending on whether the user account exists, which allows remote attackers to enumerate usernames via a series of SOAP requests to machine.aspx.
network
low complexity
ipswitch CWE-200
5.3
2016-02-10 CVE-2015-7679 Cross-site Scripting vulnerability in Ipswitch Moveit Mobile 1.2.0.962
Cross-site scripting (XSS) vulnerability in Ipswitch MOVEit Mobile before 1.2.2 allows remote attackers to inject arbitrary web script or HTML via the query string to mobile/.
network
low complexity
ipswitch CWE-79
6.1
2016-02-10 CVE-2015-7677 Information Exposure vulnerability in Ipswitch Moveit DMZ 8.1
The MOVEitISAPI service in Ipswitch MOVEit DMZ before 8.2 provides different error messages depending on whether a FileID exists, which allows remote authenticated users to enumerate FileIDs via the X-siLock-FileID parameter in a download action to MOVEitISAPI/MOVEitISAPI.dll.
network
low complexity
ipswitch CWE-200
4.3
2016-02-10 CVE-2015-7675 Information Exposure vulnerability in Ipswitch Moveit DMZ and Moveit Mobile
The "Send as attachment" feature in Ipswitch MOVEit DMZ before 8.2 and MOVEit Mobile before 1.2.2 allow remote authenticated users to bypass authorization and read uploaded files via a valid FileID in the (1) serverFileIds parameter to mobile/sendMsg or (2) arg01 parameter to human.aspx.
network
low complexity
ipswitch CWE-200
6.5