NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
87812 | CVE-2017-11180 | FineCMS through 2017-07-11 has stored XSS in the logging functionality, as demonstrated by an XSS payload in (1) the User-Agent header of an HTTP request or (2) the username entered on the login screen. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-16 | View | |
87823 | CVE-2017-11198 | Cross-site scripting (XSS) vulnerability in /application/lib/ajax/get_image.php in FineCMS through 2017-07-12 allows remote attackers to inject arbitrary web script or HTML via the folder, id, or name parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-16 | View | |
87824 | CVE-2017-11200 | SQL Injection exists in FineCMS through 2017-07-12 via the application/core/controller/excludes.php visitor_ip parameter. | 2 | 6.5 | Medium | 2017-07-18 | 2017-07-16 | View | |
87825 | CVE-2017-11201 | application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS attacks by uploading an image via a route=images action. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-16 | View | |
87826 | CVE-2017-11202 | FineCMS through 2017-07-12 allows XSS in visitors.php because JavaScript in visited URLs is not restricted either during logging or during the reading of logs, a different vulnerability than CVE-2017-11180. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-16 | View |
Page 17550 of 17672, showing 5 records out of 88360 total, starting on record 87746, ending on 87750