NVD List
Id | Name | Description | Reject | CVSS Version | CVSS Score | Severity | Pub Date | Modified Date | Actions |
---|---|---|---|---|---|---|---|---|---|
83550 | CVE-2014-8706 | Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to an array; or (4) changing the image parameter to a string, which reveals the installation path in an error message. | 2 | 5 | Medium | 2017-03-29 | 2017-03-27 | View | |
83549 | CVE-2014-8705 | PHP remote file inclusion vulnerability in editInplace.php in Wonder CMS 2014 allows remote attackers to execute arbitrary PHP code via a URL in the hook parameter. | 2017-03-18 | 2017-03-17 | View | ||||
83548 | CVE-2014-8704 | Directory traversal vulnerability in index.php in Wonder CMS 2014 allows remote attackers to include and execute arbitrary local files via a crafted theme. | 2017-03-18 | 2017-03-17 | View | ||||
83547 | CVE-2014-8703 | Cross-site scripting (XSS) vulnerability in Wonder CMS 2014 allows remote attackers to inject arbitrary web script or HTML. | 2017-03-18 | 2017-03-17 | View | ||||
83546 | CVE-2014-8702 | Wonder CMS 2014 allows remote attackers to obtain sensitive information by logging into the application with an array for the password, which reveals the installation path in an error message. | 2017-03-18 | 2017-03-17 | View |
Page 963 of 17672, showing 5 records out of 88360 total, starting on record 4811, ending on 4815