CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
96656 | CVE-2016-9836 | Candidate | The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to upload and execute files with the `.php6`, `.php7`, `.phtml`, and `.phpt` extensions. Additionally, JHelperMedia::canUpload() did not blacklist these file extensions as uploadable file types. | Assigned (20161205) | None (candidate not yet proposed) | View | |
96657 | CVE-2016-9837 | Candidate | An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content article view allow users to view articles that should not be publicly accessible, as demonstrated by an index.php?option=com_content&view=article&id=1&template=beez3 request. | Assigned (20161205) | None (candidate not yet proposed) | View | |
96658 | CVE-2016-9838 | Candidate | An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored to the session on a validation error enables a user to gain access to a registered user"s account and reset the user"s group mappings, username, and password, as demonstrated by submitting a form that targets the `registration.register` task. | Assigned (20161205) | None (candidate not yet proposed) | View | |
96659 | CVE-2016-9839 | Candidate | In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails. | Assigned (20161205) | None (candidate not yet proposed) | View | |
96660 | CVE-2016-9840 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20161205) | None (candidate not yet proposed) | View |
Page 19332 of 20943, showing 5 records out of 104715 total, starting on record 96656, ending on 96660