CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102188  CVE-2017-5368  Candidate  ZoneMinder v1.30 and v1.29, an open-source CCTV server web application, is vulnerable to CSRF (Cross Site Request Forgery) which allows a remote attack to make changes to the web application as the current logged in victim. If the victim visits a malicious web page, the attacker can silently and automatically create a new admin user within the web application for remote persistence and further attacks. The URL is /zm/index.php and sample parameters could include action=user uid=0 newUser[Username]=attacker1 newUser[Password]=Password1234 conf_password=Password1234 newUser[System]=Edit (among others).  Assigned (20170113)  None (candidate not yet proposed)    View
102189  CVE-2017-5369  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170113)  None (candidate not yet proposed)    View
102190  CVE-2017-5370  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170113)  None (candidate not yet proposed)    View
102191  CVE-2017-5371  Candidate  Odata Server in SAP Adaptive Server Enterprise (ASE) 16 allows remote attackers to cause a denial of service (process crash) via a series of crafted requests, aka SAP Security Note 2330422.  Assigned (20170113)  None (candidate not yet proposed)    View
102192  CVE-2017-5372  Candidate  The function msp (aka MSPRuntimeInterface) in the P4 SERVERCORE component in SAP AS JAVA allows remote attackers to obtain sensitive system information by leveraging a missing authorization check for the (1) getInformation, (2) getParameters, (3) getServiceInfo, (4) getStatistic, or (5) getClientStatistic function, aka SAP Security Note 2331908.  Assigned (20170113)  None (candidate not yet proposed)    View

Page 19800 of 20943, showing 5 records out of 104715 total, starting on record 98996, ending on 99000

Actions