Show filters
4 Total Results
Displaying 1-4 of 4
Sort by:
Attacker Value
Unknown

CVE-2018-25016

Disclosure Date: June 21, 2021 (last updated February 22, 2025)
Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
Attacker Value
Unknown

CVE-2019-25047

Disclosure Date: June 21, 2021 (last updated February 22, 2025)
Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling in gsad.
Attacker Value
Unknown

CVE-2016-1926

Disclosure Date: January 26, 2016 (last updated November 25, 2024)
Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers to inject arbitrary web script or HTML via the aggregate_type parameter in a get_aggregate command to omp.
0
Attacker Value
Unknown

CVE-2011-0650

Disclosure Date: January 28, 2011 (last updated October 04, 2023)
Cross-site request forgery (CSRF) vulnerability in Greenbone Security Assistant (GSA) before 2.0+rc3 allows remote attackers to hijack the authentication of users for requests that send email via an OMP request to OpenVAS Manager. NOTE: this issue can be leveraged to bypass authentication requirements for exploiting CVE-2011-0018.
0