NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86535  CVE-2017-9365  CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?force=false. A page with id=1 can be unlocked.    6.8  Medium  2017-06-12  2017-06-06  View
86534  CVE-2017-9364  Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety check and execute any code.    7.5  High  2017-06-12  2017-06-06  View
86533  CVE-2017-9363  Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted authentication request.    7.5  High  2017-06-12  2017-06-09  View
86532  CVE-2017-9361  WebsiteBaker v2.10.0 has a stored XSS vulnerability in /account/details.php.    4.3  Medium  2017-06-12  2017-06-06  View
86531  CVE-2017-9360  WebsiteBaker v2.10.0 has a SQL injection vulnerability in /account/details.php.    7.5  High  2017-06-12  2017-06-06  View

Page 366 of 17672, showing 5 records out of 88360 total, starting on record 1826, ending on 1830

Actions