CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
102700 | CVE-2017-5880 | Candidate | Splunk Web in Splunk Enterprise versions 6.5.x before 6.5.2, 6.4.x before 6.4.5, 6.3.x before 6.3.9, 6.2.x before 6.2.13, 6.1.x before 6.1.12, 6.0.x before 6.0.13, 5.0.x before 5.0.17 and Splunk Light versions before 6.5.2 allows remote authenticated users to cause a denial of service (daemon crash) via a crafted GET request, aka SPL-130279. | Assigned (20170203) | None (candidate not yet proposed) | View | |
102699 | CVE-2017-5879 | Candidate | An issue was discovered in Exponent CMS 2.4.1. This is a blind SQL injection that can be exploited by un-authenticated users via an HTTP GET request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects source_selector.php and the following parameter: src. | Assigned (20170203) | None (candidate not yet proposed) | View | |
102698 | CVE-2017-5878 | Candidate | ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided. | Assigned (20170203) | None (candidate not yet proposed) | View | |
102697 | CVE-2017-5877 | Candidate | XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter. | Assigned (20170202) | None (candidate not yet proposed) | View | |
102696 | CVE-2017-5876 | Candidate | XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter. | Assigned (20170202) | None (candidate not yet proposed) | View |
Page 404 of 20943, showing 5 records out of 104715 total, starting on record 2016, ending on 2020