CVE List

Id CVE No. Status Description Phase Votes Comments Actions
94601  CVE-2016-7781  Candidate  SQL injection vulnerability in framework/modules/blog/controllers/blogController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the author parameter.  Assigned (20160909)  None (candidate not yet proposed)    View
94602  CVE-2016-7782  Candidate  SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the src parameter.  Assigned (20160909)  None (candidate not yet proposed)    View
94603  CVE-2016-7783  Candidate  SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.  Assigned (20160909)  None (candidate not yet proposed)    View
94604  CVE-2016-7784  Candidate  SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.  Assigned (20160909)  None (candidate not yet proposed)    View
94605  CVE-2016-7785  Candidate  The avi_read_seek function in libavformat/avidec.c in FFmpeg before 3.1.4 allows remote attackers to cause a denial of service (assert fault) via a crafted AVI file.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 18921 of 20943, showing 5 records out of 104715 total, starting on record 94601, ending on 94605

Actions