Show filters
70 Total Results
Displaying 61-70 of 70
Sort by:
Attacker Value
Unknown
CVE-2011-3707
Disclosure Date: September 23, 2011 (last updated October 04, 2023)
JanRain PHP OpenID library (aka php-openid) 2.2.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by Auth/Yadis/Yadis.php and certain other files.
0
Attacker Value
Unknown
CVE-2010-3685
Disclosure Date: September 29, 2010 (last updated October 04, 2023)
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not checking for reuse of openid.response_nonce values, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
0
Attacker Value
Unknown
CVE-2010-3091
Disclosure Date: September 29, 2010 (last updated October 04, 2023)
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not verifying the openid.return_to value, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
0
Attacker Value
Unknown
CVE-2010-3686
Disclosure Date: September 29, 2010 (last updated October 04, 2023)
The OpenID module in Drupal 6.x before 6.18, and the OpenID module 5.x before 5.x-1.4 for Drupal, violates the OpenID 2.0 protocol by not ensuring that fields are signed, which allows remote attackers to bypass authentication by leveraging an assertion from an OpenID provider.
0
Attacker Value
Unknown
CVE-2008-6835
Disclosure Date: June 27, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in OpenID 5.x before 5.x-1.2, a module for Drupal, allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2008-6836
Disclosure Date: June 27, 2009 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in OpenID 5.x before 5x.-1.2, a module for Drupal, allows remote attackers to hijack the authentication of unspecified victims to delete OpenID identities via unknown vectors.
0
Attacker Value
Unknown
CVE-2008-0570
Disclosure Date: February 05, 2008 (last updated October 04, 2023)
The OpenID 5.x-1.0 and earlier module for Drupal does not properly verify the claimed_id returned by an OpenID provider, which allows remote OpenID providers to spoof OpenID authentication for domains associated with other providers.
0
Attacker Value
Unknown
CVE-2007-5173
Disclosure Date: October 03, 2007 (last updated October 04, 2023)
PHP remote file inclusion vulnerability in includes/openid/Auth/OpenID/BBStore.php in phpBB Openid 0.2.0 allows remote attackers to execute arbitrary PHP code via a URL in the openid_root_path parameter.
0
Attacker Value
Unknown
CVE-2007-1651
Disclosure Date: March 24, 2007 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in OpenID allows remote attackers to restore the login session of a user on an OpenID enabled site via unspecified vectors related to an arbitrary remote web site and cached tokens, after the user has signed into an OpenID server, logged into the OpenID enabled site, and then logged out of the OpenID enabled site.
0
Attacker Value
Unknown
CVE-2007-1652
Disclosure Date: March 24, 2007 (last updated October 04, 2023)
OpenID allows remote attackers to forcibly log a user into an OpenID enabled site, divulge the user's personal information to this site, and add it site to the trusted sites list via a crafted web page, related to cached tokens.
0