NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
22469  CVE-2016-9835  Directory traversal vulnerability in file "jcss.php" in Zikula 1.3.x before 1.3.11 and 1.4.x before 1.4.4 on Windows allows a remote attacker to launch a PHP object injection by uploading a serialized file.    7.5  High  2017-01-19  2016-12-27  View
22470  CVE-2016-9836  The file scanning mechanism of JFilterInput::isFileSafe() in Joomla! CMS before 3.6.5 does not consider alternative PHP file extensions when checking uploaded files for PHP content, which enables a user to upload and execute files with the `.php6`, `.php7`, `.phtml`, and `.phpt` extensions. Additionally, JHelperMedia::canUpload() did not blacklist these file extensions as uploadable file types.    7.5  High  2017-01-19  2016-12-07  View
22471  CVE-2016-9837  An issue was discovered in templates/beez3/html/com_content/article/default.php in Joomla! before 3.6.5. Inadequate permissions checks in the Beez3 layout override of the com_content article view allow users to view articles that should not be publicly accessible, as demonstrated by an index.php?option=com_content&view=article&id=1&template=beez3 request.    Medium  2017-01-19  2016-12-22  View
22472  CVE-2016-9838  An issue was discovered in components/com_users/models/registration.php in Joomla! before 3.6.5. Incorrect filtering of registration form data stored to the session on a validation error enables a user to gain access to a registered user"s account and reset the user"s group mappings, username, and password, as demonstrated by submitting a form that targets the `registration.register` task.    Medium  2017-01-19  2016-12-22  View
22473  CVE-2016-9839  In MapServer before 7.0.3, OGR driver error messages are too verbose and may leak sensitive information if data connection fails.    Medium  2017-01-19  2016-12-14  View

Page 16661 of 17672, showing 5 records out of 88360 total, starting on record 83301, ending on 83305

Actions