NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
88342 | CVE-2017-5246 | Biscom Secure File Transfer is vulnerable to AngularJS expression injection in the Display Name field. An authenticated user can populate this field with a valid AngularJS expression, wrapped in double curly-braces ({{ }}). This expression will be evaluated by any other authenticated user who views the attacker's display name. | 2017-07-18 | 2017-07-18 | View | ||||
88341 | CVE-2017-5245 | ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none. | 1 | 2017-07-18 | 2017-07-18 | View | |||
86943 | CVE-2017-5244 | Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests. Only POST requests should have been allowed, as the stop/stop_all routes change the state of the service. This could have allowed an attacker to stop currently-running Metasploit tasks by getting an authenticated user to execute JavaScript. As of Metasploit 4.14.0 (Update 2017061301), the routes for stopping tasks only allow POST requests, which validate the presence of a secret token to prevent CSRF attacks. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-05 | View | |
86625 | CVE-2017-5243 | The default SSH configuration in Rapid7 Nexpose hardware appliances shipped before June 2017 does not specify desired algorithms for key exchange and other important functions. As a result, it falls back to allowing ALL algorithms supported by the relevant version of OpenSSH and makes the installations vulnerable to a range of MITM, downgrade, and decryption attacks. | 2 | 6.8 | Medium | 2017-06-17 | 2017-06-14 | View | |
87483 | CVE-2017-5241 | Biscom Secure File Transfer version 5.1.1015 (and possibly prior) is vulnerable to post-authentication persistent cross-site scripting (XSS) in the Name and Description fields of a Workspace, as well as the Description field of a File Details pane of a file stored in a Workspace. This issue has been resolved in version 5.1.1025. | 2 | 3.5 | Low | 2017-07-18 | 2017-07-06 | View |
Page 489 of 17672, showing 5 records out of 88360 total, starting on record 2441, ending on 2445