CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104206  CVE-2017-7386  Candidate  citymont/symetrie v.0.9.6 is vulnerable to a reflected XSS in symetrie-master/app/commands/page.php (model parameter).  Assigned (20170331)  None (candidate not yet proposed)    View
104207  CVE-2017-7387  Candidate  TheFirstQuestion/HelpMeWatchWho before 2017-03-28 is vulnerable to a reflected XSS in HelpMeWatchWho-master/unaired.php (episodeID parameter).  Assigned (20170331)  None (candidate not yet proposed)    View
104208  CVE-2017-7388  Candidate  A Cross-Site Scripting (XSS) was discovered in "wallacepos v1.4.1". The vulnerability exists due to insufficient filtration of user-supplied data (token) passed to the "wallacepos-master/myaccount/resetpassword.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170331)  None (candidate not yet proposed)    View
104209  CVE-2017-7389  Candidate  Multiple Cross-Site Scripting (XSS) were discovered in "openeclass Release_3.5.4". The vulnerabilities exist due to insufficient filtration of user-supplied data (meeting_id, user) passed to the "openeclass-master/modules/tc/webconf/webconf.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170331)  None (candidate not yet proposed)    View
104210  CVE-2017-7390  Candidate  A Cross-Site Scripting (XSS) was discovered in "SocialNetwork v1.2.1". The vulnerability exists due to insufficient filtration of user-supplied data (mail) passed to the "SocialNetwork-andrea/app/template/pw_forgot.php" URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website.  Assigned (20170331)  None (candidate not yet proposed)    View

Page 20842 of 20943, showing 5 records out of 104715 total, starting on record 104206, ending on 104210

Actions