CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
87713 | CVE-2016-10202 | Candidate | Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the path info to index.php. | Assigned (20170204) | None (candidate not yet proposed) | View | |
87714 | CVE-2016-10203 | Candidate | Cross-site scripting (XSS) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to inject arbitrary web script or HTML via the name when creating a new monitor. | Assigned (20170204) | None (candidate not yet proposed) | View | |
87715 | CVE-2016-10204 | Candidate | SQL injection vulnerability in Zoneminder 1.30 and earlier allows remote attackers to execute arbitrary SQL commands via the limit parameter in a log query request to index.php. | Assigned (20170204) | None (candidate not yet proposed) | View | |
87716 | CVE-2016-10205 | Candidate | Session fixation vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack web sessions via the ZMSESSID cookie. | Assigned (20170204) | None (candidate not yet proposed) | View | |
87717 | CVE-2016-10206 | Candidate | Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requests that change passwords and possibly have unspecified other impact as demonstrated by a crafted user action request to index.php. | Assigned (20170204) | None (candidate not yet proposed) | View |
Page 19918 of 20943, showing 5 records out of 104715 total, starting on record 99586, ending on 99590