CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102881  CVE-2017-6061  Candidate  Cross-site scripting (XSS) vulnerability in the help component of SAP BusinessObjects Financial Consolidation 10.0.0.1933 allows remote attackers to inject arbitrary web script or HTML via a GET request. /finance/help/en/frameset.htm is the URI for this component. The vendor response is SAP Security Note 2368106.  Assigned (20170217)  None (candidate not yet proposed)    View
102882  CVE-2017-6062  Candidate  The "OpenID Connect Relying Party and OAuth 2.0 Resource Server" (aka mod_auth_openidc) module before 2.1.5 for the Apache HTTP Server does not skip OIDC_CLAIM_ and OIDCAuthNHeader headers in an "OIDCUnAuthAction pass" configuration, which allows remote attackers to bypass authentication via crafted HTTP traffic.  Assigned (20170217)  None (candidate not yet proposed)    View
102883  CVE-2017-6063  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170217)  None (candidate not yet proposed)    View
102884  CVE-2017-6064  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170217)  None (candidate not yet proposed)    View
102885  CVE-2017-6065  Candidate  SQL injection vulnerability in inc/lib/Control/Backend/menus.control.php in GeniXCMS through 1.0.2 allows remote authenticated users to execute arbitrary SQL commands via the order parameter.  Assigned (20170217)  None (candidate not yet proposed)    View

Page 20577 of 20943, showing 5 records out of 104715 total, starting on record 102881, ending on 102885

Actions