CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
94606 | CVE-2016-7786 | Candidate | Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. This is fixed in 10.6.5. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94607 | CVE-2016-7787 | Candidate | A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94608 | CVE-2016-7788 | Candidate | SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94609 | CVE-2016-7789 | Candidate | SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter. | Assigned (20160909) | None (candidate not yet proposed) | View | |
94610 | CVE-2016-7790 | Candidate | Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload "php" file to the website through uploader_paste.php, then overwrite /framework/conf/config.php, which leads to arbitrary code execution. | Assigned (20160909) | None (candidate not yet proposed) | View |
Page 18922 of 20943, showing 5 records out of 104715 total, starting on record 94606, ending on 94610