NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
81657  CVE-2017-5570  An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the messageJson.jsp, which can only be exploited by authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile().    6.5  Medium  2017-02-07  2017-01-26  View
81660  CVE-2017-5574  SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows unauthenticated users to execute arbitrary SQL commands via the activation parameter.    7.5  High  2017-02-07  2017-01-26  View
81661  CVE-2017-5575  SQL injection vulnerability in inc/lib/Options.class.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the modules parameter.    7.5  High  2017-02-07  2017-01-26  View
32775  CVE-2014-4877  Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink.    9.3  High  2017-01-30  2017-01-25  View
17423  CVE-2016-10033  The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted Sender property.    7.5  High  2017-01-30  2017-01-25  View

Page 2364 of 17672, showing 5 records out of 88360 total, starting on record 11816, ending on 11820

Actions