CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102165  CVE-2017-5345  Candidate  SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.  Assigned (20170111)  None (candidate not yet proposed)    View
102164  CVE-2017-5344  Candidate  An issue was discovered in dotCMS through 3.6.1. The findChildrenByFilter() function which is called by the web accessible path /categoriesServlet performs string interpolation and direct SQL query execution. SQL quote escaping and a keyword blacklist were implemented in a new class, SQLUtil (main/java/com/dotmarketing/common/util/SQLUtil.java), as part of the remediation of CVE-2016-8902; however, these can be overcome in the case of the q and inode parameters to the /categoriesServlet path. Overcoming these controls permits a number of blind boolean SQL injection vectors in either parameter. The /categoriesServlet web path can be accessed remotely and without authentication in a default dotCMS deployment.  Assigned (20170111)  None (candidate not yet proposed)    View
102163  CVE-2017-5343  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170111)  None (candidate not yet proposed)    View
102162  CVE-2017-5342  Candidate  In tcpdump before 4.9.0, a bug in multiple protocol parsers (Geneve, GRE, NSH, OTV, VXLAN and VXLAN GPE) could cause a buffer overflow in print-ether.c:ether_print().  Assigned (20170111)  None (candidate not yet proposed)    View
102161  CVE-2017-5341  Candidate  The OTV parser in tcpdump before 4.9.0 has a buffer overflow in print-otv.c:otv_print().  Assigned (20170111)  None (candidate not yet proposed)    View

Page 511 of 20943, showing 5 records out of 104715 total, starting on record 2551, ending on 2555

Actions