CVE List
| Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
|---|---|---|---|---|---|---|---|
| 102359 | CVE-2017-5539 | Candidate | The patch for directory traversal (CVE-2017-5480) in b2evolution version 6.8.4-stable has a bypass vulnerability. An attacker can use ../ to bypass the filter rule. Then, this attacker can exploit this vulnerability to delete or read any files on the server. It can also be used to determine whether a file exists. | Assigned (20170119) | None (candidate not yet proposed) | View | |
| 102360 | CVE-2017-5540 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170119) | None (candidate not yet proposed) | View | |
| 102361 | CVE-2017-5541 | Candidate | Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to rename arbitrary files via a .. (dot dot) in the existing-folder and new-folder parameters. | Assigned (20170119) | None (candidate not yet proposed) | View | |
| 102362 | CVE-2017-5542 | Candidate | Cross-site scripting (XSS) vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remote attackers to inject arbitrary web script or HTML via the existing-folder parameter. | Assigned (20170119) | None (candidate not yet proposed) | View | |
| 102363 | CVE-2017-5543 | Candidate | includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request. | Assigned (20170119) | None (candidate not yet proposed) | View |
Page 1109 of 20943, showing 5 records out of 104715 total, starting on record 5541, ending on 5545