CVE List

Id CVE No. Status Description Phase Votes Comments Actions
96108  CVE-2016-9288  Candidate  In framework/modules/navigation/controllers/navigationController.php in Exponent CMS v2.4.0 or older, the parameter "target" of function "DragnDropReRank" is directly used without any filtration which caused SQL injection. The payload can be used like this: /navigation/DragnDropReRank/target/1.  Assigned (20161111)  None (candidate not yet proposed)    View
96109  CVE-2016-9289  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161111)  None (candidate not yet proposed)    View
96110  CVE-2016-9290  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161111)  None (candidate not yet proposed)    View
96111  CVE-2016-9291  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161111)  None (candidate not yet proposed)    View
96112  CVE-2016-9292  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20161111)  None (candidate not yet proposed)    View

Page 18615 of 20943, showing 5 records out of 104715 total, starting on record 93071, ending on 93075

Actions