NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
65376  CVE-2006-6833  com_categories in Joomla! before 1.0.12 does not validate input, which has unknown impact and remote attack vectors.    7.5  High  2016-12-20  2011-03-07  View
10292  CVE-2011-3720  conceptcms 5.3.1, 5.3.3, and possibly other versions allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by sys_libs/umlib/um_authserver.inc.php and certain other files.    Medium  2017-01-07  2011-10-20  View
10293  CVE-2011-3721  concrete 5.4.0.5, 5.4.1, and 5.4.1.1 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by tools/spellchecker_service.php and certain other files.    Medium  2017-01-07  2012-03-13  View
85041  CVE-2017-8082  concrete5 8.1.0 has CSRF in Thumbnail Editor in the File Manager, which allows remote attackers to disable the entire installation by merely tricking an admin into viewing a malicious page involving the /tools/required/files/importers/imageeditor?fID=1&imgData= URI. This results in a site-wide denial of service making the site not accessible to any users or any administrators.    4.3  Medium  2017-05-07  2017-04-27  View
84943  CVE-2017-7725  concrete5 8.1.0 places incorrect trust in the HTTP Host header during caching, if the administrator did not define a canonical URL on installation of concrete5 using the Advanced Options settings. Remote attackers can make a GET request with any domain name in the Host header; this is stored and allows for arbitrary domains to be set for certain links displayed to subsequent visitors, potentially an XSS vector.    4.3  Medium  2017-04-27  2017-04-20  View

Page 2640 of 17672, showing 5 records out of 88360 total, starting on record 13196, ending on 13200

Actions