Show filters
152 Total Results
Displaying 131-140 of 152
Sort by:
Attacker Value
Unknown
CVE-2014-8302
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4, 6.0.x before 6.0.6, and 5.0.x before 5.0.10 allows remote attackers to inject arbitrary web script or HTML via vectors related to dashboard.
0
Attacker Value
Unknown
CVE-2014-8301
Disclosure Date: October 16, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 5.0.x before 5.0.10 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer header.
0
Attacker Value
Unknown
CVE-2014-3147
Disclosure Date: October 10, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in the auto-complete feature in Splunk Enterprise before 6.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a CSV file.
0
Attacker Value
Unknown
CVE-2014-5197
Disclosure Date: August 12, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in (1) Splunk Web or the (2) Splunkd HTTP Server in Splunk Enterprise 6.1.x before 6.1.3 allows remote authenticated users to read arbitrary files via a .. (dot dot) in a URI, related to search ids.
0
Attacker Value
Unknown
CVE-2014-5198
Disclosure Date: August 12, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.3 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.
0
Attacker Value
Unknown
CVE-2013-7394
Disclosure Date: August 07, 2014 (last updated October 05, 2023)
The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string. NOTE: this issue was SPLIT from CVE-2013-6771 per ADT2 due to different vulnerability types.
0
Attacker Value
Unknown
CVE-2013-6771
Disclosure Date: August 07, 2014 (last updated October 05, 2023)
Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the file parameter. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2013-7394 is for the issue in the "runshellscript echo.sh" script.
0
Attacker Value
Unknown
CVE-2014-2578
Disclosure Date: April 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk before 5.0.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2012-6447
Disclosure Date: January 23, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk 5.0.0 through 5.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2013-6870
Disclosure Date: November 25, 2013 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0