NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83430 | CVE-2017-6570 | A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign-list.php with the GET Parameter: id. | 2 | 6.5 | Medium | 2017-03-18 | 2017-03-13 | View | |
85471 | CVE-2017-6565 | On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the roleDiag user, which can be obtained by exploiting CVE-2013-7247, has the ability to upload files to the server hosting the web service. As no sanitization checks are in place, an attacker can upload a malicious payload. | 2 | 6.5 | Medium | 2017-05-27 | 2017-05-12 | View | |
85470 | CVE-2017-6564 | On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive system files from the host machine such as databases which contain information that can aid in further attacks. | 2 | 4 | Medium | 2017-05-27 | 2017-05-12 | View | |
83429 | CVE-2017-6562 | XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=file&targetObjId=fileFolder-2&targetObjIdChild=[XSS] attack. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-17 | View | |
83428 | CVE-2017-6561 | XSS in Agora-Project 3.2.2 exists with an index.php?ctrl=object&action=[XSS] attack. | 2 | 4.3 | Medium | 2017-03-18 | 2017-03-17 | View |
Page 358 of 17672, showing 5 records out of 88360 total, starting on record 1786, ending on 1790