CVE List

Id CVE No. Status Description Phase Votes Comments Actions
103617  CVE-2017-6797  Candidate  A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the "action_type" parameter.  Assigned (20170309)  None (candidate not yet proposed)    View
103375  CVE-2017-6555  Candidate  Cross-site scripting (XSS) vulnerability in /admin/moduleinterface.php in CMS Made Simple 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the m1_description parameter (aka "Design Manager > Categories > Category Description").  Assigned (20170309)  None (candidate not yet proposed)    View
103376  CVE-2017-6556  Candidate  Cross-site scripting (XSS) vulnerability in CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated users to inject arbitrary web script or HTML via the "adminpage > sitesetting > General Settings > globalmetadata" field.  Assigned (20170309)  None (candidate not yet proposed)    View
103377  CVE-2017-6557  Candidate  ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new security problem. When the candidate has been publicized, the details for this candidate will be provided.  Assigned (20170309)  None (candidate not yet proposed)    View
103378  CVE-2017-6558  Candidate  iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the password.cgi file.  Assigned (20170309)  None (candidate not yet proposed)    View

Page 865 of 20943, showing 5 records out of 104715 total, starting on record 4321, ending on 4325

Actions