CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87713  CVE-2016-10202  Candidate  Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the path info to index.php.  Assigned (20170204)  None (candidate not yet proposed)    View
87714  CVE-2016-10203  Candidate  Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the name when creating a new monitor.  Assigned (20170204)  None (candidate not yet proposed)    View
87715  CVE-2016-10204  Candidate  SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php.  Assigned (20170204)  None (candidate not yet proposed)    View
87716  CVE-2016-10205  Candidate  Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMSESSID cookie.  Assigned (20170204)  None (candidate not yet proposed)    View
87717  CVE-2016-10206  Candidate  Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requests that change passwords and possibly have unspecified other impact as demonstrated by a crafted user action request to index.php.  Assigned (20170204)  None (candidate not yet proposed)    View

Page 1027 of 20943, showing 5 records out of 104715 total, starting on record 5131, ending on 5135

Actions