NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
20874 | CVE-2016-5653 | Multiple SQL injection vulnerabilities in Misys FusionCapital Opics Plus allow remote authenticated users to execute arbitrary SQL commands via the (1) ID or (2) Branch parameter. | 2 | 4 | Medium | 2017-01-19 | 2016-11-28 | View | |
20875 | CVE-2016-5654 | Misys FusionCapital Opics Plus allows remote authenticated users to gain privileges via a man-in-the-middle attack that modifies the xmlMessageOut parameter. | 2 | 8.5 | High | 2017-01-19 | 2016-11-28 | View | |
20876 | CVE-2016-5655 | Misys FusionCapital Opics Plus does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to obtain sensitive information via a crafted certificate. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
20877 | CVE-2016-5660 | Cross-site scripting (XSS) vulnerability in AttachmentsList.aspx in Accela Civic Platform Citizen Access portal allows remote attackers to inject arbitrary web script or HTML via the iframeid parameter. | 2 | 4.3 | Medium | 2017-01-19 | 2016-11-28 | View | |
20878 | CVE-2016-5661 | Accela Civic Platform Citizen Access portal relies on the client to restrict file types for uploads, which allows remote authenticated users to execute arbitrary code via modified _EventArgument and filename parameters. | 2 | 6.5 | Medium | 2017-01-19 | 2016-11-28 | View |
Page 16149 of 17672, showing 5 records out of 88360 total, starting on record 80741, ending on 80745