CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
104145 | CVE-2017-7325 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170330) | None (candidate not yet proposed) | View | |
104144 | CVE-2017-7324 | Candidate | setup/templates/findcore.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the core_path parameter. | Assigned (20170330) | None (candidate not yet proposed) | View | |
104143 | CVE-2017-7323 | Candidate | The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code by leveraging the lack of the HTTPS protection mechanism. | Assigned (20170330) | None (candidate not yet proposed) | View | |
104142 | CVE-2017-7322 | Candidate | The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code via a crafted certificate. | Assigned (20170330) | None (candidate not yet proposed) | View | |
104141 | CVE-2017-7321 | Candidate | setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the setup/index.php?action=welcome URI. | Assigned (20170330) | None (candidate not yet proposed) | View |
Page 115 of 20943, showing 5 records out of 104715 total, starting on record 571, ending on 575