CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104445  CVE-2017-7625  Candidate  In Fiyo CMS 2.x through 2.0.7, attackers may upload a webshell via the content parameter to "/dapur/apps/app_theme/libs/save_file.php" and then execute code.  Assigned (20170410)  None (candidate not yet proposed)    View
39165  CVE-2009-1730  Candidate  Multiple directory traversal vulnerabilities in NetMechanica NetDecision TFTP Server 4.2 allow remote attackers to read or modify arbitrary files via directory traversal sequences in the (1) GET or (2) PUT command.  Assigned (20090520)  None (candidate not yet proposed)    View
104701  CVE-2017-7881  Candidate  BigTree CMS through 4.2.17 relies on a substring check for CSRF protection, which allows remote attackers to bypass this check by placing the required admin/developer/ URI within a query string in an HTTP Referer header. This was found in core/admin/modules/developer/_header.php and patched in core/inc/bigtree/admin.php on 2017-04-14.  Assigned (20170415)  None (candidate not yet proposed)    View
39421  CVE-2009-1986  Candidate  Unspecified vulnerability in the Oracle Applications Manager component in Oracle E-Business Suite 11.5.10.2 allows remote attackers to affect confidentiality via unknown vectors.  Assigned (20090608)  None (candidate not yet proposed)    View
39677  CVE-2009-2242  Candidate  SQL injection vulnerability in active_appointments.asp in ASP Inline Corporate Calendar allows remote attackers to execute arbitrary SQL commands via the order parameter.  Assigned (20090627)  None (candidate not yet proposed)    View

Page 20762 of 20943, showing 5 records out of 104715 total, starting on record 103806, ending on 103810

Actions