NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
26609  CVE-2015-5457  PivotX before 2.3.11 does not validate the new file extension when renaming a file with multiple extensions, which allows remote attackers to execute arbitrary code by uploading a crafted file, as demonstrated by a file named foo.php.php.    7.5  High  2017-01-19  2015-08-11  View
26608  CVE-2015-5456  Cross-site scripting (XSS) vulnerability in the form method in modules/formclass.php in PivotX before 2.3.11 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO, related to the "PHP_SELF" variable and form actions.    4.3  Medium  2017-01-19  2015-08-11  View
26607  CVE-2015-5455  Cross-site scripting (XSS) vulnerability in X-Cart 4.5.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors to install/.    4.3  Medium  2017-01-19  2015-07-09  View
26606  CVE-2015-5454  Cross-site scripting (XSS) vulnerability in Nucleus CMS 3.65 allows remote attackers to inject arbitrary web script or HTML via the title parameter when adding a new item.    4.3  Medium  2017-01-19  2016-12-07  View
26605  CVE-2015-5453  Watchguard XCS 9.2 and 10.0 before build 150522 allow remote authenticated users to execute arbitrary commands via shell metacharacters in the id parameter to ADMIN/mailqueue.spl.    6.5  Medium  2017-01-19  2016-11-28  View

Page 3033 of 17672, showing 5 records out of 88360 total, starting on record 15161, ending on 15165

Actions