NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
17435  CVE-2016-10074  The mail transport (aka Swift_Transport_MailTransport) in Swift Mailer before 5.4.5 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted e-mail address in the (1) From, (2) ReturnPath, or (3) Sender header.    7.5  High  2017-01-19  2017-01-03  View
17438  CVE-2016-10082  include/functions_installer.inc.php in Serendipity through 2.0.5 is vulnerable to File Inclusion and a possible Code Execution attack during a first-time installation because it fails to sanitize the dbType POST parameter before adding it to an include() call in the bundled-libs/serendipity_generateFTPChecksums.php file.    7.5  High  2017-01-19  2017-01-03  View
17439  CVE-2016-10083  Cross-site scripting (XSS) vulnerability in admin/plugin.php in Piwigo through 2.8.3 allows remote attackers to inject arbitrary web script or HTML via a crafted filename that is mishandled in a certain error case.    4.3  Medium  2017-01-19  2017-01-03  View
17440  CVE-2016-10084  admin/batch_manager.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the $page["tab"] variable (aka the mode parameter).    6.5  Medium  2017-01-19  2017-01-03  View
17441  CVE-2016-10085  admin/languages.php in Piwigo through 2.8.3 allows remote authenticated administrators to conduct File Inclusion attacks via the tab parameter.    6.5  Medium  2017-01-19  2017-01-03  View

Page 14918 of 17672, showing 5 records out of 88360 total, starting on record 74586, ending on 74590

Actions