NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86192 | CVE-2017-9068 | In MODX Revolution before 2.5.7, an attacker is able to trigger Reflected XSS by injecting payloads into several fields on the setup page, as demonstrated by the database_type parameter. | 2 | 4.3 | Medium | 2017-06-03 | 2017-05-30 | View | |
85937 | CVE-2017-5870 | Multiple cross-site scripting (XSS) vulnerabilities in ViMbAdmin 3.0.15 allow remote attackers to inject arbitrary web script or HTML via the (1) domain or (2) transport parameter to domain/add; the (3) name parameter to mailbox/add/did/<domain id>; the (4) goto parameter to alias/add/did/<domain id>; or the (5) captchatext parameter to auth/lost-password. | 2 | 3.5 | Low | 2017-06-03 | 2017-06-01 | View | |
86193 | CVE-2017-9069 | In MODX Revolution before 2.5.7, a user with file upload permissions is able to execute arbitrary code by uploading a file with the name .htaccess. | 2 | 6.5 | Medium | 2017-06-03 | 2017-05-30 | View | |
86194 | CVE-2017-9070 | In MODX Revolution before 2.5.7, a user with resource edit permissions can inject an XSS payload into the title of any post via the pagetitle parameter to connectors/index.php. | 2 | 3.5 | Low | 2017-06-03 | 2017-05-30 | View | |
86195 | CVE-2017-9071 | In MODX Revolution before 2.5.7, an attacker might be able to trigger XSS by injecting a payload into the HTTP Host header of a request. This is exploitable only in conjunction with other issues such as Cache Poisoning. | 2 | 2.6 | Low | 2017-06-03 | 2017-05-30 | View |
Page 1565 of 17672, showing 5 records out of 88360 total, starting on record 7821, ending on 7825