CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
96101 | CVE-2016-9281 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20161111) | None (candidate not yet proposed) | View | |
96102 | CVE-2016-9282 | Candidate | SQL Injection in framework/modules/search/controllers/searchController.php in Exponent CMS v2.4.0 allows remote attackers to read database information via action=search&module=search with the search_string parameter. | Assigned (20161111) | None (candidate not yet proposed) | View | |
96103 | CVE-2016-9283 | Candidate | SQL Injection in framework/core/subsystems/expRouter.php in Exponent CMS v2.4.0 allows remote attackers to read database information via address/addContentToSearch/id/ and a trailing string, related to a "sef URL" issue. | Assigned (20161111) | None (candidate not yet proposed) | View | |
96104 | CVE-2016-9284 | Candidate | getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via users/getUsersByJSON/sort/ and a trailing string. | Assigned (20161111) | None (candidate not yet proposed) | View | |
96105 | CVE-2016-9285 | Candidate | framework/modules/addressbook/controllers/addressController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via a modified id number, as demonstrated by address/edit/id/1, related to an "addresses, countries, and regions" issue. | Assigned (20161111) | None (candidate not yet proposed) | View |
Page 19221 of 20943, showing 5 records out of 104715 total, starting on record 96101, ending on 96105