NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86688 | CVE-2017-9442 | ** DISPUTED ** BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename patterns such as cache/package/xxx/yyy.php. This issue exists in coreadminmodulesdeveloperextensionsinstallunpack.php and coreadminmodulesdeveloperpackagesinstallunpack.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files. | 2 | 6.5 | Medium | 2017-06-12 | 2017-06-09 | View | |
86689 | CVE-2017-9443 | ** DISPUTED ** BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in coreadminmodulesdeveloperextensionsinstallprocess.php and coreadminmodulesdeveloperpackagesinstallprocess.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files. | 2 | 6.5 | Medium | 2017-06-12 | 2017-06-09 | View | |
86694 | CVE-2017-9452 | Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter. | 2 | 3.5 | Low | 2017-06-12 | 2017-06-09 | View | |
86700 | CVE-2017-9470 | In ytnef 1.9.2, the MAPIPrint function in lib/ytnef.c allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file. | 2 | 4.3 | Medium | 2017-06-12 | 2017-06-09 | View | |
86701 | CVE-2017-9471 | In ytnef 1.9.2, the SwapWord function in lib/ytnef.c allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted file. | 2 | 4.3 | Medium | 2017-06-12 | 2017-06-09 | View |
Page 16170 of 17672, showing 5 records out of 88360 total, starting on record 80846, ending on 80850