NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
16521  CVE-2010-5315  Multiple cross-site request forgery (CSRF) vulnerabilities in BEdita before 3.1 allow remote attackers to hijack the authentication of administrators for requests that (1) create categories via a data array to news/saveCategories or (2) modify credentials via a data array to admin/saveUser.    6.8  Medium  2017-01-18  2015-01-05  View
16522  CVE-2010-5316  Cross-site scripting (XSS) vulnerability in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to inject arbitrary web script or HTML via a top_height cookie.    4.3  Medium  2017-01-18  2015-01-05  View
16523  CVE-2010-5317  Multiple SQL injection vulnerabilities in index.php in SweetRice CMS before 0.6.7.1 allow remote attackers to execute arbitrary SQL commands via (1) the file_name parameter in an attachment action, (2) the post parameter in a show_comment action, (3) the sys-name parameter in an rssfeed action, or (4) the sys-name parameter in a view action.    7.5  High  2017-01-18  2015-01-05  View
16524  CVE-2010-5318  The password-reset feature in as/index.php in SweetRice CMS before 0.6.7.1 allows remote attackers to modify the administrator"s password by specifying the administrator"s e-mail address in the email parameter.    4.3  Medium  2017-01-18  2015-01-05  View
16525  CVE-2010-5319  Multiple cross-site request forgery (CSRF) vulnerabilities in Kandidat CMS 1.4.2 allow remote attackers to hijack the authentication of administrators for requests that (1) modify settings via a validate action to admin/settings.php, (2) modify pages via the what parameter to admin/edit.php, or (3) modify articles via the edit parameter to admin/news.php.    6.8  Medium  2017-01-18  2015-01-05  View

Page 3305 of 17672, showing 5 records out of 88360 total, starting on record 16521, ending on 16525

Actions