Show filters
83 Total Results
Displaying 61-70 of 83
Sort by:
Attacker Value
Unknown
Multiple SAML libraries may allow authentication bypass via incorrect XML cano…
Disclosure Date: April 17, 2019 (last updated November 27, 2024)
OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.
0
Attacker Value
Unknown
Multiple SAML libraries may allow authentication bypass via incorrect XML cano…
Disclosure Date: April 17, 2019 (last updated November 27, 2024)
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.
0
Attacker Value
Unknown
CVE-2016-6342
Disclosure Date: June 27, 2017 (last updated November 26, 2024)
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
0
Attacker Value
Unknown
CVE-2016-5697
Disclosure Date: January 23, 2017 (last updated November 25, 2024)
Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.
0
Attacker Value
Unknown
CVE-2015-6512
Disclosure Date: August 18, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute arbitrary SQL commands via the time parameter to server/freichat.php.
0
Attacker Value
Unknown
CVE-2014-3808
Disclosure Date: May 21, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) role parameter to roles.lsp, (2) name parameter to user.lsp, (3) path parameter to wizard/setuser.lsp, (4) host parameter to tunnelconstr.lsp, or (5) newpath parameter to wfsconstr.lsp in rtl/protected/admin/.
0
Attacker Value
Unknown
CVE-2013-3535
Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_email, (2) header_title, (3) site_title parameter to admin/settings; (4) recaptcha_private or (5) recaptcha_public parameter to admin/captcha_settings; (6) fb_appid, (7) fp_secret, (8) tw_consumer_key, or (9) tw_consumer_secret parameter to admin/social_settings; (10) slug parameter to admin/gallery/save_item_settings; or (11) item_link parameter to admin/edit_menu_item_ajax. NOTE: this issue might be resultant from CSRF.
0
Attacker Value
Unknown
CVE-2009-3315
Disclosure Date: September 23, 2009 (last updated October 04, 2023)
SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field.
0
Attacker Value
Unknown
CVE-2008-7004
Disclosure Date: August 19, 2009 (last updated October 04, 2023)
Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c.
0
Attacker Value
Unknown
CVE-2008-0444
Disclosure Date: January 25, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecified components.
0