CVE List

Id CVE No. Status Description Phase Votes Comments Actions
87596  CVE-2016-10096  Candidate  SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the activation parameter.  Assigned (20170101)  None (candidate not yet proposed)    View
87590  CVE-2016-10090  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161231)  None (candidate not yet proposed)    View
87591  CVE-2016-10091  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161231)  None (candidate not yet proposed)    View
87581  CVE-2016-10082  Candidate  include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it fails to sanitize the dbType POST parameter before adding it to an include() call in the bundled-libs/serendipity_generateFTPChecksums.php file.  Assigned (20161230)  None (candidate not yet proposed)    View
87582  CVE-2016-10083  Candidate  Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a certain error case.  Assigned (20161230)  None (candidate not yet proposed)    View

Page 1226 of 20943, showing 5 records out of 104715 total, starting on record 6126, ending on 6130

Actions