CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102890  CVE-2017-6070  Candidate  CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to execute PHP code via the cntnt01fbrp_forma_form_template parameter in admin_store_form.  Assigned (20170217)  None (candidate not yet proposed)    View
102889  CVE-2017-6069  Candidate  Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.  Assigned (20170217)  None (candidate not yet proposed)    View
102888  CVE-2017-6068  Candidate  Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.  Assigned (20170217)  None (candidate not yet proposed)    View
102887  CVE-2017-6067  Candidate  Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field.  Assigned (20170217)  None (candidate not yet proposed)    View
102886  CVE-2017-6066  Candidate  Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.  Assigned (20170217)  None (candidate not yet proposed)    View

Page 366 of 20943, showing 5 records out of 104715 total, starting on record 1826, ending on 1830

Actions