CVE List

Id CVE No. Status Description Phase Votes Comments Actions
104515  CVE-2017-7695  Candidate  Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an "xxx.php[space]" file, they could bypass a safety check and execute any code.  Assigned (20170411)  None (candidate not yet proposed)    View
104514  CVE-2017-7694  Candidate  Remote Code Execution vulnerability in symphony/content/content.blueprintsdatasources.php in Symphony CMS through 2.6.11 allows remote attackers to execute code and get a webshell from the back-end. The attacker must be authenticated and enter PHP code in the datasource editor or event editor.  Assigned (20170411)  None (candidate not yet proposed)    View
104513  CVE-2017-7693  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170411)  None (candidate not yet proposed)    View
104512  CVE-2017-7692  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170411)  None (candidate not yet proposed)    View
104511  CVE-2017-7691  Candidate  A code injection vulnerability exists in SAP TREX / Business Warehouse Accelerator (BWA). The vendor response is SAP Security Note 2419592.  Assigned (20170411)  None (candidate not yet proposed)    View

Page 41 of 20943, showing 5 records out of 104715 total, starting on record 201, ending on 205

Actions