NVD List

Id Name Description Reject CVSS Version CVSS Score Severity Pub Date Modified Date Actions
86691  CVE-2017-9448  Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in coreadminajaxpagessave-revision.php and coreadminmodulespages evisions.php. Low-privileged (administrator) users can attack high-privileged (Developer) users.    3.5  Low  2017-06-17  2017-06-12  View
87401  CVE-2017-9445  In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it.    Medium  2017-07-18  2017-07-06  View
86690  CVE-2017-9444  BigTree CMS through 4.2.18 has CSRF related to the coreadminmodulesusersprofileupdate.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the index.php/admin/developer/upgrade/ignore/?versions= URI, and the index.php/admin/developer/upgrade/set-ftp-directory/ URI.    6.8  Medium  2017-06-17  2017-06-12  View
86689  CVE-2017-9443  ** DISPUTED ** BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in coreadminmodulesdeveloperextensionsinstallprocess.php and coreadminmodulesdeveloperpackagesinstallprocess.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files.    6.5  Medium  2017-06-12  2017-06-09  View
86688  CVE-2017-9442  ** DISPUTED ** BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename patterns such as cache/package/xxx/yyy.php. This issue exists in coreadminmodulesdeveloperextensionsinstallunpack.php and coreadminmodulesdeveloperpackagesinstallunpack.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files.    6.5  Medium  2017-06-12  2017-06-09  View

Page 56 of 17672, showing 5 records out of 88360 total, starting on record 276, ending on 280

Actions