CVE List

Id CVE No. Status Description Phase Votes Comments Actions
94606  CVE-2016-7786  Candidate  Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. This is fixed in 10.6.5.  Assigned (20160909)  None (candidate not yet proposed)    View
94607  CVE-2016-7787  Candidate  A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.  Assigned (20160909)  None (candidate not yet proposed)    View
94608  CVE-2016-7788  Candidate  SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.  Assigned (20160909)  None (candidate not yet proposed)    View
94609  CVE-2016-7789  Candidate  SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter.  Assigned (20160909)  None (candidate not yet proposed)    View
94610  CVE-2016-7790  Candidate  Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload "php" file to the website through uploader_paste.php, then overwrite /framework/conf/config.php, which leads to arbitrary code execution.  Assigned (20160909)  None (candidate not yet proposed)    View

Page 18922 of 20943, showing 5 records out of 104715 total, starting on record 94606, ending on 94610

Actions