Show filters
93 Total Results
Displaying 51-60 of 93
Sort by:
Attacker Value
Unknown
CVE-2017-16775
Disclosure Date: April 01, 2019 (last updated November 27, 2024)
Improper restriction of rendered UI layers or frames vulnerability in SSOOauth.cgi in Synology SSO Server before 2.1.3-0129 allows remote attackers to conduct clickjacking attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2019-10015
Disclosure Date: March 24, 2019 (last updated November 27, 2024)
baigoStudio baigoSSO v3.0.1 allows remote attackers to execute arbitrary PHP code via the first form field of a configuration screen, because this code is written to the BG_SITE_NAME field in the opt_base.inc.php file.
0
Attacker Value
Unknown
CVE-2018-15528
Disclosure Date: August 21, 2018 (last updated November 27, 2024)
Reflected Cross-Site Scripting exists in the Java System Solutions SSO plugin 4.0.13.1 for BMC MyIT. A remote attacker can abuse this issue to inject client-side scripts into the "select_sso()" function. The payload is triggered when the victim opens a prepared /ux/jss-sso/arslogin?[XSS] link and then clicks the "Login" button.
0
Attacker Value
Unknown
CVE-2017-8989
Disclosure Date: August 06, 2018 (last updated November 27, 2024)
A security vulnerability in HPE IceWall SSO Dfw 10.0 and 11.0 on RHEL, HP-UX, and Windows could be exploited remotely to allow URL Redirection.
0
Attacker Value
Unknown
CVE-2018-1256
Disclosure Date: May 07, 2018 (last updated November 26, 2024)
Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.
0
Attacker Value
Unknown
CVE-2017-8978
Disclosure Date: February 15, 2018 (last updated November 26, 2024)
A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Products version MFA 4.0 proxy was found.
0
Attacker Value
Unknown
CVE-2017-14760
Disclosure Date: September 27, 2017 (last updated November 26, 2024)
SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrence_id parameter to /wp-admin/admin.php.
0
Attacker Value
Unknown
CVE-2017-1002026
Disclosure Date: September 14, 2017 (last updated November 26, 2024)
Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize user-supplied input via the $id parameter before passing it into an SQL statement.
0
Attacker Value
Unknown
CVE-2015-1401
Disclosure Date: August 28, 2017 (last updated November 26, 2024)
Improper Authentication vulnerability in the "LDAP / SSO Authentication" (ig_ldap_sso_auth) extension 2.0.0 for TYPO3.
0
Attacker Value
Unknown
CVE-2015-1783
Disclosure Date: August 11, 2017 (last updated November 26, 2024)
The prefix variable in the get_or_define_ns function in Lasso before commit 6d854cef4211cdcdbc7446c978f23ab859847cdd allows remote attackers to cause a denial of service (uninitialized memory access and application crash) via unspecified vectors.
0