CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102916  CVE-2017-6096  Candidate  A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/lists/view-list.php (Requires authentication to Wordpress admin) with the GET Parameter: filter_list.  Assigned (20170218)  None (candidate not yet proposed)    View
102917  CVE-2017-6097  Candidate  A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign/count_of_send.php (Requires authentication to Wordpress admin) with the POST Parameter: camp_id.  Assigned (20170218)  None (candidate not yet proposed)    View
102918  CVE-2017-6098  Candidate  A SQL injection issue was discovered in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects /inc/campaign_save.php (Requires authentication to Wordpress admin) with the POST Parameter: list_id.  Assigned (20170218)  None (candidate not yet proposed)    View
102919  CVE-2017-6099  Candidate  Cross-site scripting (XSS) vulnerability in GetAuthDetails.html.php in PayPal PHP Merchant SDK (aka merchant-sdk-php) 3.9.1 allows remote attackers to inject arbitrary web script or HTML via the token parameter.  Assigned (20170218)  None (candidate not yet proposed)    View
102920  CVE-2017-6100  Candidate  tcpdf before 6.2.0 uploads files from the server generating PDF-files to an external FTP.  Assigned (20170219)  None (candidate not yet proposed)    View

Page 20584 of 20943, showing 5 records out of 104715 total, starting on record 102916, ending on 102920

Actions