NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86682  CVE-2017-9436  TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.    7.5  High  2017-06-17  2017-06-13  View
86683  CVE-2017-9437  Openbravo Business Suite 3.0 is affected by SQL injection. This vulnerability could allow remote authenticated attackers to inject arbitrary SQL code.    6.5  Medium  2017-06-17  2017-06-13  View
86687  CVE-2017-9441  ** DISPUTED ** Multiple cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML by uploading a crafted package, triggering mishandling of the (1) title or (2) version or (3) author_name parameter in manifest.json. This issue exists in coreadminmodulesdeveloperextensionsinstallunpack.php and coreadminmodulesdeveloperpackagesinstallunpack.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files.    3.5  Low  2017-06-17  2017-06-12  View
86690  CVE-2017-9444  BigTree CMS through 4.2.18 has CSRF related to the coreadminmodulesusersprofileupdate.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the index.php/admin/developer/upgrade/ignore/?versions= URI, and the index.php/admin/developer/upgrade/set-ftp-directory/ URI.    6.8  Medium  2017-06-17  2017-06-12  View
86691  CVE-2017-9448  Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in coreadminajaxpagessave-revision.php and coreadminmodulespages evisions.php. Low-privileged (administrator) users can attack high-privileged (Developer) users.    3.5  Low  2017-06-17  2017-06-12  View

Page 16190 of 17672, showing 5 records out of 88360 total, starting on record 80946, ending on 80950

Actions