NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 17423 | CVE-2016-10033 | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted Sender property. | 2 | 7.5 | High | 2017-01-30 | 2017-01-25 | View | |
| 17424 | CVE-2016-10034 | The setFrom function in the Sendmail adapter in the zend-mail component before 2.4.11, 2.5.x, 2.6.x, and 2.7.x before 2.7.2, and Zend Framework before 2.4.11 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted e-mail address. | 2 | 7.5 | High | 2017-01-19 | 2017-01-03 | View | |
| 17425 | CVE-2016-10037 | Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted id (aka dir) parameter, related to browser/directory/getlist. | 2 | 7.5 | High | 2017-01-19 | 2016-12-30 | View | |
| 17426 | CVE-2016-10038 | Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/remove. | 2 | 7.5 | High | 2017-01-19 | 2016-12-29 | View | |
| 17427 | CVE-2016-10039 | Directory traversal in /connectors/index.php in MODX Revolution before 2.5.2-pl allows remote attackers to perform local file inclusion/traversal/manipulation via a crafted dir parameter, related to browser/directory/getfiles. | 2 | 7.5 | High | 2017-01-19 | 2016-12-29 | View |
Page 15341 of 17672, showing 5 records out of 88360 total, starting on record 76701, ending on 76705