Vulnerabilities

DATE CVE VULNERABILITY TITLE RISK
2017-03-07 CVE-2016-9019 SQL Injection vulnerability in Exponentcms Exponent CMS
SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.
network
low complexity
exponentcms CWE-89
critical
9.8
2017-03-07 CVE-2016-8863 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
Heap-based buffer overflow in the create_url_list function in gena/gena_device.c in Portable UPnP SDK (aka libupnp) before 1.6.21 allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via a valid URI followed by an invalid one in the CALLBACK header of an SUBSCRIBE request.
network
low complexity
libupnp-project debian CWE-119
critical
9.8
2017-03-07 CVE-2016-7789 SQL Injection vulnerability in Exponentcms Exponent CMS
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter.
network
low complexity
exponentcms CWE-89
critical
9.8
2017-03-07 CVE-2016-7788 SQL Injection vulnerability in Exponentcms Exponent CMS
SQL injection vulnerability in framework/modules/users/models/user.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the username parameter.
network
low complexity
exponentcms CWE-89
critical
9.8
2017-03-07 CVE-2016-7784 SQL Injection vulnerability in Exponentcms Exponent CMS
SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter.
network
low complexity
exponentcms CWE-89
critical
9.8
2017-03-07 CVE-2016-7783 SQL Injection vulnerability in Exponentcms Exponent CMS
SQL injection vulnerability in framework/core/models/expRecord.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the title parameter.
network
low complexity
exponentcms CWE-89
critical
9.8
2017-03-07 CVE-2016-7782 SQL Injection vulnerability in Exponentcms Exponent CMS
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the src parameter.
network
low complexity
exponentcms CWE-89
critical
9.8
2017-03-07 CVE-2016-7781 SQL Injection vulnerability in Exponentcms Exponent CMS
SQL injection vulnerability in framework/modules/blog/controllers/blogController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the author parameter.
network
low complexity
exponentcms CWE-89
critical
9.8
2017-03-07 CVE-2016-7780 SQL Injection vulnerability in Exponentcms Exponent CMS
SQL injection vulnerability in cron/find_help.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the version parameter.
network
low complexity
exponentcms CWE-89
critical
9.8
2017-03-07 CVE-2016-7140 Cross-site Scripting vulnerability in Plone
Multiple cross-site scripting (XSS) vulnerabilities in the ZMI page in Zope2 in Plone CMS 5.x through 5.0.6, 4.x through 4.3.11, and 3.3.x through 3.3.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
plone CWE-79
6.1