Show filters
45 Total Results
Displaying 41-45 of 45
Sort by:
Attacker Value
Unknown
CVE-2014-0941
Disclosure Date: May 01, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in webtop/eventviewer/eventViewer.jsp in the Web GUI in IBM Netcool/OMNIbus 7.4.0 before FP2 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL, a different vulnerability than CVE-2014-0942.
0
Attacker Value
Unknown
CVE-2013-4509
Disclosure Date: November 23, 2013 (last updated October 05, 2023)
The default configuration of IBUS 1.5.4, and possibly 1.5.2 and earlier, when IBus.InputPurpose.PASSWORD is not set and used with GNOME 3, does not obscure the entered password characters, which allows physically proximate attackers to obtain a user password by reading the lockscreen.
0
Attacker Value
Unknown
CVE-2011-1343
Disclosure Date: March 09, 2011 (last updated October 04, 2023)
SQL injection vulnerability in the Web GUI in IBM Tivoli Netcool/OMNIbus before 7.3.0.4 allows remote attackers to execute arbitrary SQL commands via "dynamic SQL parameters."
0
Attacker Value
Unknown
CVE-2011-0002
Disclosure Date: January 22, 2011 (last updated October 04, 2023)
libuser before 0.57 uses a cleartext password value of (1) !! or (2) x for new LDAP user accounts, which makes it easier for remote attackers to obtain access by specifying one of these values.
0
Attacker Value
Unknown
CVE-2005-2038
Disclosure Date: June 20, 2005 (last updated February 22, 2025)
Fortibus CMS 4.0.0 allows remote attackers to modify information of other users, including Admin, via the "My info" page.
0