Show filters
83 Total Results
Displaying 61-70 of 83
Sort by:
Attacker Value
Unknown

Multiple SAML libraries may allow authentication bypass via incorrect XML cano…

Disclosure Date: April 17, 2019 (last updated November 27, 2024)
OneLogin PythonSAML 2.3.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.
0
Attacker Value
Unknown

Multiple SAML libraries may allow authentication bypass via incorrect XML cano…

Disclosure Date: April 17, 2019 (last updated November 27, 2024)
OneLogin Ruby-SAML 1.6.0 and earlier may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.
0
Attacker Value
Unknown

CVE-2016-6342

Disclosure Date: June 27, 2017 (last updated November 26, 2024)
elog 3.1.1 allows remote attackers to post data as any username in the logbook.
Attacker Value
Unknown

CVE-2016-5697

Disclosure Date: January 23, 2017 (last updated November 25, 2024)
Ruby-saml before 1.3.0 allows attackers to perform XML signature wrapping attacks via unspecified vectors.
0
Attacker Value
Unknown

CVE-2015-6512

Disclosure Date: August 18, 2015 (last updated October 05, 2023)
SQL injection vulnerability in the get_messages function in server/plugins/chatroom/chatroom.php in FreiChat 9.6 allows remote attackers to execute arbitrary SQL commands via the time parameter to server/freichat.php.
0
Attacker Value
Unknown

CVE-2014-3808

Disclosure Date: May 21, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in BarracudaDrive before 6.7.2 allow remote attackers to inject arbitrary web script or HTML via the (1) role parameter to roles.lsp, (2) name parameter to user.lsp, (3) path parameter to wizard/setuser.lsp, (4) host parameter to tunnelconstr.lsp, or (5) newpath parameter to wfsconstr.lsp in rtl/protected/admin/.
0
Attacker Value
Unknown

CVE-2013-3535

Disclosure Date: May 13, 2013 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in CMSLogik 1.2.0 and 1.2.1 allow remote attackers to inject arbitrary web script or HTML via the (1) admin_email, (2) header_title, (3) site_title parameter to admin/settings; (4) recaptcha_private or (5) recaptcha_public parameter to admin/captcha_settings; (6) fb_appid, (7) fp_secret, (8) tw_consumer_key, or (9) tw_consumer_secret parameter to admin/social_settings; (10) slug parameter to admin/gallery/save_item_settings; or (11) item_link parameter to admin/edit_menu_item_ajax. NOTE: this issue might be resultant from CSRF.
0
Attacker Value
Unknown

CVE-2009-3315

Disclosure Date: September 23, 2009 (last updated October 04, 2023)
SQL injection vulnerability in admin/index.php in NeLogic Nephp Publisher Enterprise 3.5.9 and 4.5 allows remote attackers to execute arbitrary SQL commands via the Username field.
0
Attacker Value
Unknown

CVE-2008-7004

Disclosure Date: August 19, 2009 (last updated October 04, 2023)
Buffer overflow in Electronic Logbook (ELOG) before 2.7.1 has unknown impact and attack vectors, possibly related to elog.c.
0
Attacker Value
Unknown

CVE-2008-0444

Disclosure Date: January 25, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in Electronic Logbook (ELOG) before 2.7.0 allows remote attackers to inject arbitrary web script or HTML via subtext parameter to unspecified components.
0