[Secure-testing-commits] [Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso carnil at debian.org
Mon Feb 12 16:09:24 UTC 2018


Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d1b77ae9 by Salvatore Bonaccorso at 2018-02-12T17:09:17+01:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
--- a/data/CVE/list
+++ b/data/CVE/list
@@ -50,9 +50,9 @@ CVE-2018-6891 (Bookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a
 CVE-2018-6890
 	RESERVED
 CVE-2018-6889 (An issue was discovered in Typesetter 5.1. It suffers from a Host ...)
-	TODO: check
+	NOT-FOR-US: Typesetter CMS
 CVE-2018-6888 (An issue was discovered in Typesetter 5.1. The User Permissions page ...)
-	TODO: check
+	NOT-FOR-US: Typesetter CMS
 CVE-2018-6887
 	RESERVED
 CVE-2018-6886
@@ -76,9 +76,9 @@ CVE-2018-1000060 (Sensu, Inc. Sensu Core version Before 1.2.0 & before commi
 CVE-2018-1000059 (ValidFormBuilder version 4.5.4 contains a PHP Object Injection ...)
 	NOT-FOR-US: ValidFormBuilder
 CVE-2018-6881 (EmpireCMS 6.6 allows remote attackers to discover the full path via an ...)
-	TODO: check
+	NOT-FOR-US: EmpireCMS
 CVE-2018-6880 (EmpireCMS 6.6 through 7.2 allows remote attackers to discover the full ...)
-	TODO: check
+	NOT-FOR-US: EmpireCMS
 CVE-2018-6879
 	RESERVED
 CVE-2018-6878 (Cross Site Scripting (XSS) exists in the review section in PHP Scripts ...)
@@ -121,19 +121,19 @@ CVE-2018-6866
 CVE-2018-6865
 	RESERVED
 CVE-2018-6864 (Cross Site Scripting (XSS) exists in PHP Scripts Mall Multi religion ...)
-	TODO: check
+	NOT-FOR-US: PHP Scripts Mall Multi religion Responsive Matrimonial
 CVE-2018-6863 (SQL Injection exists in PHP Scripts Mall Select Your College Script ...)
-	TODO: check
+	NOT-FOR-US: PHP Scripts Mall Select Your College Script
 CVE-2018-6862 (Cross Site Scripting (XSS) exists in PHP Scripts Mall Bitcoin MLM ...)
-	TODO: check
+	NOT-FOR-US: PHP Scripts Mall Bitcoin MLM Software
 CVE-2018-6861 (Cross Site Scripting (XSS) exists in PHP Scripts Mall Lawyer Search ...)
-	TODO: check
+	NOT-FOR-US: PHP Scripts Mall Lawyer Search Script
 CVE-2018-6860 (Arbitrary File Upload and Remote Code Execution exist in PHP Scripts ...)
-	TODO: check
+	NOT-FOR-US: PHP Scripts Mall Schools Alert Management Script
 CVE-2018-6859
 	RESERVED
 CVE-2018-6858 (Cross Site Scripting (XSS) exists in PHP Scripts Mall Facebook Clone ...)
-	TODO: check
+	NOT-FOR-US: PHP Scripts Mall Facebook Clone Script
 CVE-2018-6857
 	RESERVED
 CVE-2018-6856
@@ -159,7 +159,7 @@ CVE-2018-6847
 CVE-2018-6846 (Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a ...)
 	NOT-FOR-US: Z-BlogPHP
 CVE-2018-6845 (PHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the ...)
-	TODO: check
+	NOT-FOR-US: PHP Scripts Mall Multi Language Olx Clone Script
 CVE-2018-6844 (MyBB 1.8.14 has XSS via the Title or Description field on the Edit ...)
 	NOT-FOR-US: MyBB
 CVE-2018-6843



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/d1b77ae93845477b74a81dd874a917642541b413

---
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/commit/d1b77ae93845477b74a81dd874a917642541b413
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.alioth.debian.org/pipermail/secure-testing-commits/attachments/20180212/efb7455c/attachment-0001.html>


More information about the Secure-testing-commits mailing list