CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104020  CVE-2017-7200  Candidate  An SSRF issue was discovered in OpenStack Glance before Newton. The "copy_from" feature in the Image Service API v1 allowed an attacker to perform masked network port scans. With v1, it is possible to create images with a URL such as "http://localhost:22". This could then allow an attacker to enumerate internal network details while appearing masked, since the scan would appear to originate from the Glance Image service.  Assigned (20170320)  None (candidate not yet proposed)    View
104021  CVE-2017-7201  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170321)  None (candidate not yet proposed)    View
104022  CVE-2017-7202  Candidate  Multiple Cross-Site Scripting (XSS) were discovered in SLiMS 7 Cendana before 2017-03-16. The vulnerabilities exist due to insufficient filtration of user-supplied data (id) passed to the "slims7_cendana-master/template/default/detail_template.php" and "slims7_cendana-master/template/default-rtl/detail_template.php" URLs. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170321)  None (candidate not yet proposed)    View
104023  CVE-2017-7203  Candidate  A Cross-Site Scripting (XSS) was discovered in ZoneMinder 1.30.2. The vulnerability exists due to insufficient filtration of user-supplied data (postLoginQuery) passed to the "ZoneMinder-master/web/skins/classic/views/js/postlogin.js.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170321)  None (candidate not yet proposed)    View
104024  CVE-2017-7204  Candidate  A Cross-Site Scripting (XSS) was discovered in imdbphp 5.1.1. The vulnerability exists due to insufficient filtration of user-supplied data (name) passed to the "imdbphp-master/demo/search.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170321)  None (candidate not yet proposed)    View

Page 20201 of 20943, showing 5 records out of 104715 total, starting on record 101001, ending on 101005

Actions