NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86534  CVE-2017-9364  Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety check and execute any code.    7.5  High  2017-06-12  2017-06-06  View
86535  CVE-2017-9365  CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?force=false. A page with id=1 can be unlocked.    6.8  Medium  2017-06-12  2017-06-06  View
86536  CVE-2017-9366  Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Base/Dashboard/Dashboard_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted tab_name parameter.    3.5  Low  2017-06-12  2017-06-09  View
86538  CVE-2017-9378  BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such as data backups) to complete before a user is deleted.    Medium  2017-06-12  2017-06-06  View
86539  CVE-2017-9379  Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to coreadminmodulesdashboardvitals-statistics404clear.php and the from or to parameter to coreadminmodulesdashboardvitals-statistics404create-301.php.    6.8  Medium  2017-06-12  2017-06-06  View

Page 1497 of 17672, showing 5 records out of 88360 total, starting on record 7481, ending on 7485

Actions