CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104110  CVE-2017-7290  Candidate  SQL injection vulnerability in XOOPS 2.5.7.2 and other versions before 2.5.8.1 allows remote authenticated administrators to execute arbitrary SQL commands via the url parameter to findusers.php. An example attack uses "into outfile" to create a backdoor program.  Assigned (20170328)  None (candidate not yet proposed)    View
104109  CVE-2017-7289  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170328)  None (candidate not yet proposed)    View
104108  CVE-2017-7288  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170328)  None (candidate not yet proposed)    View
104107  CVE-2017-7287  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170328)  None (candidate not yet proposed)    View
104106  CVE-2017-7286  Candidate  ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.  Assigned (20170327)  None (candidate not yet proposed)    View

Page 122 of 20943, showing 5 records out of 104715 total, starting on record 606, ending on 610

Actions