[Secure-testing-commits] r58909 - data/CVE
Salvatore Bonaccorso
carnil at moszumanska.debian.org
Mon Dec 25 09:34:04 UTC 2017
Author: carnil
Date: 2017-12-25 09:34:04 +0000 (Mon, 25 Dec 2017)
New Revision: 58909
Modified:
data/CVE/list
Log:
Process NFUs
Modified: data/CVE/list
===================================================================
--- data/CVE/list 2017-12-25 09:10:18 UTC (rev 58908)
+++ data/CVE/list 2017-12-25 09:34:04 UTC (rev 58909)
@@ -16,17 +16,17 @@
- dolibarr <unfixed>
NOTE: https://github.com/Dolibarr/dolibarr/commit/4a5988accbb770b74105baacd5a034689272128c
CVE-2017-17896 (Readymade Job Site Script has XSS via the keyword parameter to the /job ...)
- TODO: check
+ NOT-FOR-US: Readymade Job Site Script
CVE-2017-17895 (Readymade Job Site Script has SQL Injection via the location_name array ...)
- TODO: check
+ NOT-FOR-US: Readymade Job Site Script
CVE-2017-17894 (Readymade Job Site Script has CSRF via the /job URI. ...)
- TODO: check
+ NOT-FOR-US: Readymade Job Site Script
CVE-2017-17893 (Readymade Video Sharing Script has XSS via the search_video.php search ...)
- TODO: check
+ NOT-FOR-US: Readymade Video Sharing Script
CVE-2017-17892 (Readymade Video Sharing Script has SQL Injection via the viewsubs.php ...)
- TODO: check
+ NOT-FOR-US: Readymade Video Sharing Script
CVE-2017-17891 (Readymade Video Sharing Script has CSRF via user-profile-edit.php. ...)
- TODO: check
+ NOT-FOR-US: Readymade Video Sharing Script
CVE-2017-17890
RESERVED
CVE-2017-17889
More information about the Secure-testing-commits
mailing list