NVD List
| Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
|---|---|---|---|---|---|---|---|---|---|
| 81657 | CVE-2017-5570 | An issue was discovered in eClinicalWorks Patient Portal 7.0 build 13. This is a blind SQL injection within the messageJson.jsp, which can only be exploited by authenticated users via an HTTP POST request and which can be used to dump database data out to a malicious server, using an out-of-band technique such as select_loadfile(). | 2 | 6.5 | Medium | 2017-02-07 | 2017-01-26 | View | |
| 81660 | CVE-2017-5574 | SQL injection vulnerability in register.php in GeniXCMS before 1.0.0 allows unauthenticated users to execute arbitrary SQL commands via the activation parameter. | 2 | 7.5 | High | 2017-02-07 | 2017-01-26 | View | |
| 81661 | CVE-2017-5575 | SQL injection vulnerability in inc/lib/Options.class.php in GeniXCMS before 1.0.0 allows remote attackers to execute arbitrary SQL commands via the modules parameter. | 2 | 7.5 | High | 2017-02-07 | 2017-01-26 | View | |
| 32775 | CVE-2014-4877 | Absolute path traversal vulnerability in GNU Wget before 1.16, when recursion is enabled, allows remote FTP servers to write to arbitrary files, and consequently execute arbitrary code, via a LIST response that references the same filename within two entries, one of which indicates that the filename is for a symlink. | 2 | 9.3 | High | 2017-01-30 | 2017-01-25 | View | |
| 17423 | CVE-2016-10033 | The mailSend function in the isMail transport in PHPMailer before 5.2.18 might allow remote attackers to pass extra parameters to the mail command and consequently execute arbitrary code via a " (backslash double quote) in a crafted Sender property. | 2 | 7.5 | High | 2017-01-30 | 2017-01-25 | View |
Page 2364 of 17672, showing 5 records out of 88360 total, starting on record 11816, ending on 11820