Show filters
73 Total Results
Displaying 71-73 of 73
Sort by:
Attacker Value
Unknown

CVE-2017-5232

Disclosure Date: March 02, 2017 (last updated November 26, 2024)
All editions of Rapid7 Nexpose installers prior to version 6.4.24 contain a DLL preloading vulnerability, wherein it is possible for the installer to load a malicious DLL located in the current working directory of the installer.
0
Attacker Value
Unknown

CVE-2016-9757

Disclosure Date: December 20, 2016 (last updated November 25, 2024)
In the Create Tags page of the Rapid7 Nexpose version 6.4.12 user interface, any authenticated user who has the capability to create tags can inject cross-site scripting (XSS) elements in the tag name field. Once this tag is viewed in the Tag Detail page of the Rapid7 Nexpose 6.4.12 UI by another authenticated user, the script is run in that user's browser context.
0
Attacker Value
Unknown

CVE-2012-6493

Disclosure Date: February 04, 2014 (last updated October 05, 2023)
Cross-site request forgery (CSRF) vulnerability in Rapid7 Nexpose Security Console before 5.5.4 allows remote attackers to hijack the authentication of unspecified victims for requests that delete scan data and sites via a request to data/site/delete.
0