NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86692  CVE-2017-9449  SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core/admin/modules/developer/modules/views/create.php. The attacker creates a crafted table name at admin/developer/modules/views/create/ and the injection is visible at admin/ajax/auto-modules/views/searchable-page/ or admin/modules_name.    6.5  Medium  2017-06-17  2017-06-12  View
86693  CVE-2017-9451  Cross site scripting (XSS) vulnerability in pages.edit_form.php in flatCore 1.4.6 allows remote attackers to inject arbitrary JavaScript via the PATH_INFO in an acp.php URL, due to use of unsanitized $_SERVER['PHP_SELF'] to generate URLs.    4.3  Medium  2017-06-17  2017-06-13  View
86694  CVE-2017-9452  Cross-site scripting (XSS) vulnerability in admin.php in Piwigo 2.9.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the page parameter.    3.5  Low  2017-06-12  2017-06-09  View
86695  CVE-2017-9461  smbd in Samba before 4.4.10 and 4.5.x before 4.5.6 has a denial of service vulnerability (fd_open_atomic infinite loop with high CPU usage and memory consumption) due to wrongly handling dangling symlinks.    7.8  High  2017-06-17  2017-06-15  View
86696  CVE-2017-9462  In Mercurial before 4.1.3, hg serve --stdio allows remote authenticated users to launch the Python debugger, and consequently execute arbitrary code, by using --debugger as a repository name.    High  2017-06-23  2017-06-20  View

Page 17618 of 17672, showing 5 records out of 88360 total, starting on record 88086, ending on 88090

Actions