CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
94601 | CVE-2016-7781 | Candidate | SQL injection vulnerability in framework/modules/blog/controllers/blogController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the author parameter. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94602 | CVE-2016-7782 | Candidate | SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the src parameter. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94603 | CVE-2016-7783 | Candidate | SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94604 | CVE-2016-7784 | Candidate | SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94605 | CVE-2016-7785 | Candidate | The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file. | Assigned (20160909) | None (candidate not yet proposed) | View |
Page 18921 of 20943, showing 5 records out of 104715 total, starting on record 94601, ending on 94605