NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
87412  CVE-2017-9841  Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a <?php substring, as demonstrated by an attack on a site with an exposed /vendor folder, i.e., external access to the /vendor/phpunit/phpunit/src/Util/PHP/eval-stdin.php URI.    7.5  High  2017-07-18  2017-07-06  View
87415  CVE-2017-9848  SQL injection vulnerability in C_InfoService.asmx in WebServices in Easysite 7.0 could allow remote attackers to execute arbitrary SQL commands via an XML document containing a crafted ArticleIDs element within a GetArticleHitsArray element.    7.5  High  2017-07-18  2017-07-06  View
87943  CVE-2017-2292  Versions of MCollective prior to 2.10.4 deserialized YAML from agents without calling safe_load, allowing the potential for arbitrary code execution on the server. The fix for this is to call YAML.safe_load on input. This has been tested in all Puppet-supplied MCollective plugins, but there is a chance that third-party plugins could rely on this insecure behavior.    7.5  High  2017-07-18  2017-07-06  View
87946  CVE-2017-2298  The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to an arbitrary location on the client with the filename appended with the string _pub.pem.    4.3  Medium  2017-07-18  2017-07-06  View
87483  CVE-2017-5241  Biscom Secure File Transfer version 5.1.1015 (and possibly prior) is vulnerable to post-authentication persistent cross-site scripting (XSS) in the Name and Description fields of a Workspace, as well as the Description field of a File Details pane of a file stored in a Workspace. This issue has been resolved in version 5.1.1025.    3.5  Low  2017-07-18  2017-07-06  View

Page 16379 of 17672, showing 5 records out of 88360 total, starting on record 81891, ending on 81895

Actions