NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83837 | CVE-2017-7235 | An issue was discovered in cloudflare-scrape 1.6.6 through 1.7.1. A malicious website owner could craft a page that executes arbitrary Python code against any cfscrape user who scrapes that website. This is fixed in 1.8.0. | 2 | 6.8 | Medium | 2017-04-27 | 2017-03-30 | View | |
22472 | CVE-2016-9838 | An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored to the session on a validation error enables a user to gain access to a registered user"s account and reset the user"s group mappings, username, and password, as demonstrated by submitting a form that targets the `registration.register` task. | 2 | 5 | Medium | 2017-01-19 | 2016-12-22 | View | |
83486 | CVE-2017-6905 | An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (disable_choose) passed to the concrete5-legacy-master/web/concrete/tools/files/search_dialog.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-23 | View | |
83489 | CVE-2017-6908 | An issue was discovered in concrete5 <= 5.6.3.4. The vulnerability exists due to insufficient filtration of user-supplied data (fID) passed to the concrete5-legacy-master/web/concrete/tools/files/selector_data.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | 2 | 4.3 | Medium | 2017-03-29 | 2017-03-22 | View | |
82264 | CVE-2017-5962 | An issue was discovered in contexts_wurfl (for TYPO3) before 0.4.2. The vulnerability exists due to insufficient filtration of user-supplied data in the force_ua HTTP GET parameter passed to the /contexts_wurfl/Library/wurfl-dbapi-1.4.4.0/check_wurfl.php URL. An attacker could execute arbitrary HTML and script code in a browser in the context of the vulnerable website. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-03 | View |
Page 1146 of 17672, showing 5 records out of 88360 total, starting on record 5726, ending on 5730