CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102359  CVE-2017-5539  Candidate  The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An attacker can use ../ to bypass the filter rule. Then, this attacker can exploit this vulnerability to delete or read any files on the server. It can also be used to determine whether a file exists.  Assigned (20170119)  None (candidate not yet proposed)    View
102360  CVE-2017-5540  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170119)  None (candidate not yet proposed)    View
102361  CVE-2017-5541  Candidate  Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to rename arbitrary files via a .. (dot dot) in the existing-folder and new-folder parameters.  Assigned (20170119)  None (candidate not yet proposed)    View
102362  CVE-2017-5542  Candidate  Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to inject arbitrary web script or HTML via the existing-folder parameter.  Assigned (20170119)  None (candidate not yet proposed)    View
102363  CVE-2017-5543  Candidate  includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.  Assigned (20170119)  None (candidate not yet proposed)    View

Page 1109 of 20943, showing 5 records out of 104715 total, starting on record 5541, ending on 5545

Actions