CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102699 | CVE-2017-5879 | Candidate | An issue was discovered in Exponent CMS 2.4.1. This is a blind SQL injection that can be exploited by un-authenticated users via an HTTP GET request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects source_selector.php and the following parameter: src. | Assigned (20170203) | None (candidate not yet proposed) | View | |
102700 | CVE-2017-5880 | Candidate | Splunk Web in Splunk Enterprise versions 6.5.x before 6.5.2, 6.4.x before 6.4.5, 6.3.x before 6.3.9, 6.2.x before 6.2.13, 6.1.x before 6.1.12, 6.0.x before 6.0.13, 5.0.x before 5.0.17 and Splunk Light versions before 6.5.2 allows remote authenticated users to cause a denial of service (daemon crash) via a crafted GET request, aka SPL-130279. | Assigned (20170203) | None (candidate not yet proposed) | View | |
102701 | CVE-2017-5881 | Candidate | GOM Player 2.3.10.5266 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted fpx file. | Assigned (20170203) | None (candidate not yet proposed) | View | |
102702 | CVE-2017-5882 | Candidate | Cross-site scripting (XSS) vulnerability in index.asp in SANADATA SanaCMS 7.3 allows remote attackers to inject arbitrary web script or HTML via the search parameter. | Assigned (20170204) | None (candidate not yet proposed) | View | |
102703 | CVE-2017-5883 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170204) | None (candidate not yet proposed) | View |
Page 19916 of 20943, showing 5 records out of 104715 total, starting on record 99576, ending on 99580