Show filters
69 Total Results
Displaying 61-69 of 69
Sort by:
Attacker Value
Unknown

CVE-2014-4693

Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to inject arbitrary web script or HTML via (1) the eng parameter to snort_import_aliases.php or (2) unspecified variables to snort_select_alias.php.
0
Attacker Value
Unknown

CVE-2014-4695

Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Multiple open redirect vulnerabilities in the Snort package before 3.0.13 for pfSense through 2.1.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the referer parameter to snort_rules_flowbits.php or (2) the returl parameter to snort_select_alias.php.
0
Attacker Value
Unknown

CVE-2014-4692

Disclosure Date: July 02, 2014 (last updated October 05, 2023)
pfSense before 2.1.4, when HTTP is used, does not include the HTTPOnly flag in a Set-Cookie header for the session cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to this cookie.
0
Attacker Value
Unknown

CVE-2014-4696

Disclosure Date: July 02, 2014 (last updated October 05, 2023)
Multiple open redirect vulnerabilities in the Suricata package before 1.0.6 for pfSense through 2.1.4 allow remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via (1) the referer parameter to suricata_rules_flowbits.php or (2) the returl parameter to suricata_select_alias.php.
0
Attacker Value
Unknown

CVE-2011-5047

Disclosure Date: January 03, 2012 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in status_rrd_graph.php in pfSense before 2.0.1 allows remote attackers to inject arbitrary web script or HTML via the style parameter.
0
Attacker Value
Unknown

CVE-2011-4197

Disclosure Date: January 03, 2012 (last updated October 04, 2023)
etc/inc/certs.inc in the PKI implementation in pfSense before 2.0.1 creates each X.509 certificate with a true value for the CA basic constraint, which allows remote attackers to create sub-certificates for arbitrary subjects by leveraging the private key.
0
Attacker Value
Unknown

CVE-2010-4246

Disclosure Date: December 07, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in graph.php in pfSense 1.2.3 and 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via the (1) ifnum or (2) ifname parameter, a different vulnerability than CVE-2008-1182.
0
Attacker Value
Unknown

CVE-2010-4412

Disclosure Date: December 07, 2010 (last updated October 04, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in pfSense 2 beta 4 allow remote attackers to inject arbitrary web script or HTML via (1) the id parameter in an olsrd.xml action to pkg_edit.php, (2) the xml parameter to pkg.php, or the if parameter to (3) status_graph.php or (4) interfaces.php, a different vulnerability than CVE-2008-1182 and CVE-2010-4246.
0
Attacker Value
Unknown

CVE-2008-1182

Disclosure Date: March 06, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in BSD Perimeter pfSense before 1.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0