Show filters
11 Total Results
Displaying 1-10 of 11
Sort by:
Attacker Value
Unknown

CVE-2023-27739

Disclosure Date: January 08, 2024 (last updated January 13, 2024)
easyXDM 2.5 allows XSS via the xdm_e parameter.
Attacker Value
Unknown

CVE-2013-5212

Disclosure Date: February 14, 2020 (last updated February 21, 2025)
Cross-site Scripting (XSS) in EasyXDM before 2.4.18 allows remote attackers to inject arbitrary web script or html via the easyxdm.swf file.
Attacker Value
Unknown

CVE-2018-16960

Disclosure Date: May 02, 2019 (last updated November 27, 2024)
An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/login.php has Reflected XSS via the xd_user_formal_name parameter.
0
Attacker Value
Unknown

CVE-2018-16961

Disclosure Date: May 02, 2019 (last updated November 27, 2024)
An issue was discovered in Open XDMoD through 7.5.0. html/gui/general/dl_publication.php allows Path traversal via the file parameter, allowing remote attackers to read PDF files in arbitrary directories.
0
Attacker Value
Unknown

CVE-2018-16988

Disclosure Date: May 02, 2019 (last updated November 27, 2024)
An issue was discovered in Open XDMoD through 7.5.0. An authentication bypass (account takeover) exists due to a weak password reset mechanism. A brute-force attack against an MD5 rid value requires only 600 guesses in the plausible situation where the attacker knows that the victim has started a password-reset process (pass_reset.php, password_reset.php, XDUser.php) in the past few minutes.
Attacker Value
Unknown

CVE-2017-2625

Disclosure Date: July 27, 2018 (last updated November 27, 2024)
It was discovered that libXdmcp before 1.1.2 including used weak entropy to generate session keys. On a multi-user system using xdmcp, a local attacker could potentially use information available from the process list to brute force the key, allowing them to hijack other users' sessions.
0
Attacker Value
Unknown

CVE-2015-8308

Disclosure Date: August 24, 2017 (last updated November 26, 2024)
LXDM before 0.5.2 did not start X server with -auth, which allows local users to bypass authentication with X connections.
0
Attacker Value
Unknown

CVE-2014-1403

Disclosure Date: February 05, 2014 (last updated October 05, 2023)
Cross-site scripting (XSS) vulnerability in name.html in easyXDM before 2.4.19 allows remote attackers to inject arbitrary web script or HTML via the location.hash value.
0
Attacker Value
Unknown

CVE-2006-5215

Disclosure Date: October 10, 2006 (last updated October 04, 2023)
The Xsession script, as used by X Display Manager (xdm) in NetBSD before 20060212, X.Org before 20060317, and Solaris 8 through 10 before 20061006, allows local users to overwrite arbitrary files, or read another user's Xsession errors file, via a symlink attack on a /tmp/xses-$USER file.
0
Attacker Value
Unknown

CVE-2006-4447

Disclosure Date: August 30, 2006 (last updated October 04, 2023)
X.Org and XFree86, including libX11, xdm, xf86dga, xinit, xload, xtrans, and xterm, does not check the return values for setuid and seteuid calls when attempting to drop privileges, which might allow local users to gain privileges by causing those calls to fail, such as by exceeding a ulimit.
0