CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
96106 | CVE-2016-9286 | Candidate | framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0patch1 does not properly restrict access to user records, which allows remote attackers to read address information, as demonstrated by an address/show/id/1 URI. | Assigned (20161111) | None (candidate not yet proposed) | View | |
96107 | CVE-2016-9287 | Candidate | In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter "$term" used directly in SQL. Impact is a SQL injection. | Assigned (20161111) | None (candidate not yet proposed) | View | |
96108 | CVE-2016-9288 | Candidate | In framework/modules/navigation/controllers/navigationController.php in Exponent CMS v2.4.0 or older, the parameter "target" of function "DragnDropReRank" is directly used without any filtration which caused SQL injection. The payload can be used like this: /navigation/DragnDropReRank/target/1. | Assigned (20161111) | None (candidate not yet proposed) | View | |
96109 | CVE-2016-9289 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20161111) | None (candidate not yet proposed) | View | |
96110 | CVE-2016-9290 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20161111) | None (candidate not yet proposed) | View |
Page 19222 of 20943, showing 5 records out of 104715 total, starting on record 96106, ending on 96110