NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
81681 | CVE-2017-5677 | PEAR HTML_AJAX 0.3.0 through 0.5.7 has a PHP Object Injection Vulnerability in the PHP Serializer. It allows remote code execution. In one viewpoint, the root cause is an incorrect regular expression. | 2 | 7.5 | High | 2017-03-18 | 2017-02-28 | View | |
81682 | CVE-2017-5875 | XSS was discovered in dotCMS 3.7.0, with an authenticated attack against the /myAccount addressID parameter. | 2 | 3.5 | Low | 2017-02-15 | 2017-02-09 | View | |
81683 | CVE-2017-5876 | XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-09 | View | |
81684 | CVE-2017-5877 | XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /about-us/locations/index direction parameter. | 2 | 4.3 | Medium | 2017-02-15 | 2017-02-09 | View | |
81685 | CVE-2017-5879 | An issue was discovered in Exponent CMS 2.4.1. This is a blind SQL injection that can be exploited by un-authenticated users via an HTTP GET request and which can be used to dump database data out to a malicious server, using an out-of-band technique, such as select_loadfile(). The vulnerability affects source_selector.php and the following parameter: src. | 2 | 7.5 | High | 2017-02-15 | 2017-02-08 | View |
Page 16337 of 17672, showing 5 records out of 88360 total, starting on record 81681, ending on 81685