NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
86691 | CVE-2017-9448 | Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in coreadminajaxpagessave-revision.php and coreadminmodulespages evisions.php. Low-privileged (administrator) users can attack high-privileged (Developer) users. | 2 | 3.5 | Low | 2017-06-17 | 2017-06-12 | View | |
87401 | CVE-2017-9445 | In systemd through 233, certain sizes passed to dns_packet_new in systemd-resolved can cause it to allocate a buffer that's too small. A malicious DNS server can exploit this via a response with a specially crafted TCP payload to trick systemd-resolved into allocating a buffer that's too small, and subsequently write arbitrary data beyond the end of it. | 2 | 5 | Medium | 2017-07-18 | 2017-07-06 | View | |
86690 | CVE-2017-9444 | BigTree CMS through 4.2.18 has CSRF related to the coreadminmodulesusersprofileupdate.php script (modify user information), the index.php/admin/developer/packages/delete/ URI (remove packages), the index.php/admin/developer/upgrade/ignore/?versions= URI, and the index.php/admin/developer/upgrade/set-ftp-directory/ URI. | 2 | 6.8 | Medium | 2017-06-17 | 2017-06-12 | View | |
86689 | CVE-2017-9443 | ** DISPUTED ** BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in coreadminmodulesdeveloperextensionsinstallprocess.php and coreadminmodulesdeveloperpackagesinstallprocess.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files. | 2 | 6.5 | Medium | 2017-06-12 | 2017-06-09 | View | |
86688 | CVE-2017-9442 | ** DISPUTED ** BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename patterns such as cache/package/xxx/yyy.php. This issue exists in coreadminmodulesdeveloperextensionsinstallunpack.php and coreadminmodulesdeveloperpackagesinstallunpack.php. NOTE: the vendor states You must implicitly trust any package or extension you install as they all have the ability to write PHP files. | 2 | 6.5 | Medium | 2017-06-12 | 2017-06-09 | View |
Page 56 of 17672, showing 5 records out of 88360 total, starting on record 276, ending on 280