Show filters
154 Total Results
Displaying 131-140 of 154
Sort by:
Attacker Value
Unknown

CVE-2018-1148

Disclosure Date: May 18, 2018 (last updated November 26, 2024)
In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change.
0
Attacker Value
Unknown

CVE-2018-1147

Disclosure Date: May 18, 2018 (last updated November 26, 2024)
In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessus file, which may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session. In other scenarios, XSS could also occur by altering variables from the Advanced Settings.
0
Attacker Value
Unknown

CVE-2018-1142

Disclosure Date: March 28, 2018 (last updated November 26, 2024)
Tenable Appliance versions 4.6.1 and earlier have been found to contain a single XSS vulnerability. Utilizing a specially crafted request, an authenticated attacker could potentially execute arbitrary JavaScript code by manipulating certain URL parameters related to offline plugins.
0
Attacker Value
Unknown

CVE-2018-1141

Disclosure Date: March 20, 2018 (last updated November 26, 2024)
When installing Nessus to a directory outside of the default location, Nessus versions prior to 7.0.3 did not enforce secure permissions for sub-directories. This could allow for local privilege escalation if users had not secured the directories in the installation location.
0
Attacker Value
Unknown

CVE-2017-18214

Disclosure Date: March 04, 2018 (last updated November 26, 2024)
The moment module before 2.19.3 for Node.js is prone to a regular expression denial of service via a crafted date string, a different vulnerability than CVE-2016-4055.
Attacker Value
Unknown

CVE-2017-11508

Disclosure Date: November 02, 2017 (last updated November 26, 2024)
SecurityCenter versions 5.5.0, 5.5.1 and 5.5.2 contain a SQL Injection vulnerability that could be exploited by an authenticated user with sufficient privileges to run diagnostic scans. An attacker could exploit this vulnerability by entering a crafted SQL query into the password field of a diagnostic scan within SecurityCenter. Successful exploitation of this vulnerability could allow an attacker to gain unauthorized access.
0
Attacker Value
Unknown

CVE-2017-11506

Disclosure Date: August 09, 2017 (last updated November 26, 2024)
When linking a Nessus scanner or agent to Tenable.io or other manager, Nessus 6.x before 6.11 does not verify the manager's TLS certificate when making the initial outgoing connection. This could allow man-in-the-middle attacks.
0
Attacker Value
Unknown

CVE-2017-2122

Disclosure Date: May 12, 2017 (last updated November 26, 2024)
Cross-site scripting vulnerability in Nessus versions 6.8.0, 6.8.1, 6.9.0, 6.9.1 and 6.9.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2017-8050

Disclosure Date: April 21, 2017 (last updated November 26, 2024)
Tenable Appliance 4.4.0, and possibly prior, contains a flaw in the Web UI that allows for the unauthorized manipulation of the admin password.
0
Attacker Value
Unknown

CVE-2017-8051

Disclosure Date: April 21, 2017 (last updated November 26, 2024)
Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote attacker can inject arbitrary commands.
0