NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
84675 | CVE-2017-5156 | A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user. | 2 | 6.8 | Medium | 2017-04-27 | 2017-04-26 | View | |
84676 | CVE-2017-5158 | An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary destination addresses may be specified. | 2 | 5 | Medium | 2017-04-27 | 2017-04-26 | View | |
84677 | CVE-2017-5160 | An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly. | 2 | 3.5 | Low | 2017-04-27 | 2017-04-26 | View | |
84679 | CVE-2017-5183 | NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document. | 2 | 4.3 | Medium | 2017-04-27 | 2017-04-26 | View | |
85217 | CVE-2016-8721 | An exploitable OS Command Injection vulnerability exists in the web application "ping" functionality of Moxa AWK-3131A Wireless Access Points running firmware 1.1. Specially crafted web form input can cause an OS Command Injection resulting in complete compromise of the vulnerable device. An attacker can exploit this vulnerability remotely. | 2 | 9 | High | 2017-04-27 | 2017-04-26 | View |
Page 1754 of 17672, showing 5 records out of 88360 total, starting on record 8766, ending on 8770