CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102427 | CVE-2017-5607 | Candidate | Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage. | Assigned (20170128) | None (candidate not yet proposed) | View | |
102428 | CVE-2017-5608 | Candidate | Cross-site scripting (XSS) vulnerability in the image upload function in Piwigo before 2.8.6 allows remote attackers to inject arbitrary web script or HTML via a crafted image filename. | Assigned (20170128) | None (candidate not yet proposed) | View | |
102429 | CVE-2017-5609 | Candidate | SQL injection vulnerability in include/functions_entries.inc.php in Serendipity 2.0.5 allows remote authenticated users to execute arbitrary SQL commands via the cat parameter. | Assigned (20170128) | None (candidate not yet proposed) | View | |
102430 | CVE-2017-5610 | Candidate | wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility of a taxonomy-assignment user interface, which allows remote attackers to bypass intended access restrictions by reading terms. | Assigned (20170128) | None (candidate not yet proposed) | View | |
102431 | CVE-2017-5611 | Candidate | SQL injection vulnerability in wp-includes/class-wp-query.php in WP_Query in WordPress before 4.7.2 allows remote attackers to execute arbitrary SQL commands by leveraging the presence of an affected plugin or theme that mishandles a crafted post type name. | Assigned (20170128) | None (candidate not yet proposed) | View |
Page 1088 of 20943, showing 5 records out of 104715 total, starting on record 5436, ending on 5440