CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
87713 | CVE-2016-10202 | Candidate | Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the path info to index.php. | Assigned (20170204) | None (candidate not yet proposed) | View | |
87714 | CVE-2016-10203 | Candidate | Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the name when creating a new monitor. | Assigned (20170204) | None (candidate not yet proposed) | View | |
87715 | CVE-2016-10204 | Candidate | SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php. | Assigned (20170204) | None (candidate not yet proposed) | View | |
87716 | CVE-2016-10205 | Candidate | Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMSESSID cookie. | Assigned (20170204) | None (candidate not yet proposed) | View | |
87717 | CVE-2016-10206 | Candidate | Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requests that change passwords and possibly have unspecified other impact as demonstrated by a crafted user action request to index.php. | Assigned (20170204) | None (candidate not yet proposed) | View |
Page 1027 of 20943, showing 5 records out of 104715 total, starting on record 5131, ending on 5135