Show filters
48 Total Results
Displaying 11-20 of 48
Sort by:
Attacker Value
Unknown
CVE-2019-3996
Disclosure Date: December 17, 2019 (last updated November 08, 2023)
ELOG 3.1.4-57bea22 and below can be used as an HTTP GET request proxy when unauthenticated remote attackers send crafted HTTP POST requests.
0
Attacker Value
Unknown
CVE-2019-3992
Disclosure Date: December 17, 2019 (last updated November 08, 2023)
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can access the server's configuration file by sending an HTTP GET request. Amongst the configuration data, the attacker may gain access to valid admin usernames and, in older versions of ELOG, passwords.
0
Attacker Value
Unknown
CVE-2019-3995
Disclosure Date: December 17, 2019 (last updated November 08, 2023)
ELOG 3.1.4-57bea22 and below is affected by a denial of service vulnerability due to a NULL pointer dereference. A remote unauthenticated attacker can crash the ELOG server by sending a crafted HTTP GET request.
0
Attacker Value
Unknown
CVE-2019-3993
Disclosure Date: December 17, 2019 (last updated November 08, 2023)
ELOG 3.1.4-57bea22 and below is affected by an information disclosure vulnerability. A remote unauthenticated attacker can recover a user's password hash by sending a crafted HTTP POST request.
0
Attacker Value
Unknown
CVE-2019-10414
Disclosure Date: September 25, 2019 (last updated October 26, 2023)
Jenkins Git Changelog Plugin 2.17 and earlier stored credentials unencrypted in job config.xml files on the Jenkins master where they could be viewed by users with Extended Read permission, or access to the master file system.
0
Attacker Value
Unknown
CVE-2016-10928
Disclosure Date: August 22, 2019 (last updated November 27, 2024)
The onelogin-saml-sso plugin before 2.2.0 for WordPress has a hardcoded @@@nopass@@@ password for just-in-time provisioned users.
0
Attacker Value
Unknown
CVE-2019-0708
Disclosure Date: May 16, 2019 (last updated July 26, 2024)
A remote code execution vulnerability exists in Remote Desktop Services formerly known as Terminal Services when an unauthenticated attacker connects to the target system using RDP and sends specially crafted requests, aka 'Remote Desktop Services Remote Code Execution Vulnerability'.
0
Attacker Value
Unknown
CVE-2018-1000426
Disclosure Date: January 09, 2019 (last updated November 27, 2024)
A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly that allows attackers able to control the Git history parsed by the plugin to have Jenkins render arbitrary HTML on some pages.
0
Attacker Value
Unknown
CVE-2016-6342
Disclosure Date: June 27, 2017 (last updated November 26, 2024)
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
0
Attacker Value
Unknown
CVE-2016-4322
Disclosure Date: December 13, 2016 (last updated November 25, 2024)
BMC BladeLogic Server Automation (BSA) before 8.7 Patch 3 allows remote attackers to bypass authentication and consequently read arbitrary files or possibly have unspecified other impact by leveraging a "logic flaw" in the authentication process.
0