Show filters
175 Total Results
Displaying 171-175 of 175
Sort by:
Attacker Value
Unknown
CVE-2017-12159
Disclosure Date: October 26, 2017 (last updated November 26, 2024)
It was found that the cookie used for CSRF prevention in Keycloak was not unique to each session. An attacker could use this flaw to gain access to an authenticated user session, leading to possible information disclosure or further attacks.
0
Attacker Value
Unknown
CVE-2014-3709
Disclosure Date: October 18, 2017 (last updated November 26, 2024)
The org.keycloak.services.resources.SocialResource.callback method in JBoss KeyCloak before 1.0.3.Final allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging lack of CSRF protection.
0
Attacker Value
Unknown
CVE-2017-7474
Disclosure Date: May 12, 2017 (last updated November 26, 2024)
It was found that the Keycloak Node.js adapter 2.5 - 3.0 did not handle invalid tokens correctly. An attacker could use this flaw to bypass authentication and gain access to restricted information, or to possibly conduct further attacks.
0
Attacker Value
Unknown
CVE-2014-4563
Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in go.php in the URL Cloak & Encrypt (url-cloak-encrypt) plugin 2.0 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the url parameter.
0
Attacker Value
Unknown
CVE-2009-4784
Disclosure Date: April 21, 2010 (last updated October 04, 2023)
SQL injection vulnerability in the Joaktree (com_joaktree) component 1.0 for Joomla! allows remote attackers to execute arbitrary SQL commands via the treeId parameter to index.php.
0