NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
17423  CVE-2016-10033  The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted Sender property.    7.5  High  2017-01-30  2017-01-25  View
17424  CVE-2016-10034  The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted e-mail address.    7.5  High  2017-01-19  2017-01-03  View
17425  CVE-2016-10037  Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist.    7.5  High  2017-01-19  2016-12-30  View
17426  CVE-2016-10038  Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove.    7.5  High  2017-01-19  2016-12-29  View
17427  CVE-2016-10039  Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles.    7.5  High  2017-01-19  2016-12-29  View

Page 15341 of 17672, showing 5 records out of 88360 total, starting on record 76701, ending on 76705

Actions