CVE List

Id CVE No. Status Description Phase Votes Comments Actions
102885  CVE-2017-6065  Candidate  SQL injection vulnerability in inc/lib/Control/Backend/menus.control.php in GeniXCMS through 1.0.2 allows remote authenticated users to execute arbitrary SQL commands via the order parameter.  Assigned (20170217)  None (candidate not yet proposed)    View
102886  CVE-2017-6066  Candidate  Subrion CMS 4.0.5 has CSRF in admin/languages/edit/1/. The attacker can perform any Edit Language action, and can optionally insert XSS via the title parameter.  Assigned (20170217)  None (candidate not yet proposed)    View
102887  CVE-2017-6067  Candidate  Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field.  Assigned (20170217)  None (candidate not yet proposed)    View
102888  CVE-2017-6068  Candidate  Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.  Assigned (20170217)  None (candidate not yet proposed)    View
102889  CVE-2017-6069  Candidate  Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.  Assigned (20170217)  None (candidate not yet proposed)    View

Page 984 of 20943, showing 5 records out of 104715 total, starting on record 4916, ending on 4920

Actions