NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86192  CVE-2017-9068  In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter.    4.3  Medium  2017-06-03  2017-05-30  View
85937  CVE-2017-5870  Multiple cross-site scripting (XSS) vulnerabilities in ViMbAdmin 3.0.15 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) transport parameter to domain/add; the (3) name parameter to mailbox/add/did/<domain id>; the (4) goto parameter to alias/add/did/<domain id>; or the (5) captchatext parameter to auth/lost-password.    3.5  Low  2017-06-03  2017-06-01  View
86193  CVE-2017-9069  In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess.    6.5  Medium  2017-06-03  2017-05-30  View
86194  CVE-2017-9070  In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php.    3.5  Low  2017-06-03  2017-05-30  View
86195  CVE-2017-9071  In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning.    2.6  Low  2017-06-03  2017-05-30  View

Page 1565 of 17672, showing 5 records out of 88360 total, starting on record 7821, ending on 7825

Actions