NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
43245 | CVE-2012-1248 | app/config/core.php in baserCMS 1.6.15 and earlier does not properly handle installations in shared-hosting environments, which allows remote attackers to hijack sessions by leveraging administrative access to a different domain. | 2 | 5.1 | Medium | 2017-01-19 | 2012-05-29 | View | |
26795 | CVE-2015-5719 | app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors. | 2 | 10 | High | 2017-01-19 | 2016-11-28 | View | |
39832 | CVE-2013-4182 | app/controllers/api/v1/hosts_controller.rb in Foreman before 1.2.2 does not properly restrict access to hosts, which allows remote attackers to access arbitrary hosts via an API request. | 2 | 7.5 | High | 2017-01-18 | 2013-09-17 | View | |
23286 | CVE-2015-0854 | App/HelperFunctions.pm in Shutter through 0.93.1 allows user-assisted remote attackers to execute arbitrary commands via a crafted image name that is mishandled during a "Show in Folder" action. | 2 | 9.3 | High | 2017-01-19 | 2017-01-03 | View | |
38560 | CVE-2013-2506 | app/models/spree/user.rb in spree_auth_devise in Spree 1.1.x before 1.1.6, 1.2.x, and 1.3.x does not perform mass assignment safely when updating a user, which allows remote authenticated users to assign arbitrary roles to themselves. | 2 | 4 | Medium | 2017-01-18 | 2013-03-18 | View |
Page 1306 of 17672, showing 5 records out of 88360 total, starting on record 6526, ending on 6530