NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86675 | CVE-2017-9428 | A directory traversal vulnerability exists in coreadminajaxdeveloperextensionsfile-browser.php in BigTree CMS through 4.2.18 on Windows, allowing attackers to read arbitrary files via .. sequences in the directory parameter. | 2 | 5 | Medium | 2017-06-12 | 2017-06-06 | View | |
86674 | CVE-2017-9427 | SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via coreadminmodulesdevelopermodulesdesignerform-create.php. The attacker creates a crafted table name at admin/developer/modules/designer/ and the injection is visible at admin/dashboard/vitals-statistics/integrity/check/?external=true. | 2 | 6.5 | Medium | 2017-06-12 | 2017-06-06 | View | |
86673 | CVE-2017-9422 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-8920. Reason: This candidate is a reservation duplicate of CVE-2017-8920. Notes: All CVE users should reference CVE-2017-8920 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage. | 1 | 2017-06-12 | 2017-06-06 | View | |||
86672 | CVE-2017-9420 | Cross site scripting (XSS) vulnerability in the Spiffy Calendar plugin before 3.3.0 for WordPress allows remote attackers to inject arbitrary JavaScript via the yr parameter. | 2 | 4.3 | Medium | 2017-07-18 | 2017-07-17 | View | |
86671 | CVE-2017-9355 | XML external entity (XXE) vulnerability in the import playlist feature in Subsonic 6.1.1 might allow remote attackers to conduct server-side request forgery (SSRF) attacks via a crafted XSPF playlist file. | 2 | 4.3 | Medium | 2017-06-17 | 2017-06-16 | View |
Page 338 of 17672, showing 5 records out of 88360 total, starting on record 1686, ending on 1690