NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
22351 | CVE-2016-9287 | In /framework/modules/notfound/controllers/notfoundController.php of Exponent CMS 2.4.0 patch1, untrusted input is passed into getSearchResults. The method getSearchResults is defined in the search model with the parameter "$term" used directly in SQL. Impact is a SQL injection. | 2 | 7.5 | High | 2017-01-19 | 2016-11-29 | View | |
22350 | CVE-2016-9286 | framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0patch1 does not properly restrict access to user records, which allows remote attackers to read address information, as demonstrated by an address/show/id/1 URI. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View | |
22349 | CVE-2016-9285 | framework/modules/addressbook/controllers/addressController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via a modified id number, as demonstrated by address/edit/id/1, related to an "addresses, countries, and regions" issue. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View | |
22348 | CVE-2016-9284 | getUsersByJSON in framework/modules/users/controllers/usersController.php in Exponent CMS v2.4.0 allows remote attackers to read user information via users/getUsersByJSON/sort/ and a trailing string. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View | |
22347 | CVE-2016-9283 | SQL Injection in framework/core/subsystems/expRouter.php in Exponent CMS v2.4.0 allows remote attackers to read database information via address/addContentToSearch/id/ and a trailing string, related to a "sef URL" issue. | 2 | 5 | Medium | 2017-01-19 | 2016-11-29 | View |
Page 1066 of 17672, showing 5 records out of 88360 total, starting on record 5326, ending on 5330