Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown

CVE-2015-6237

Disclosure Date: December 27, 2017 (last updated November 26, 2024)
The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP filter restrictions via crafted "privileged commands."
0
Attacker Value
Unknown

CVE-2013-5005

Disclosure Date: January 29, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ajaxRequest/methodCall.do in Tripwire Enterprise 8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) m_target_class_name, (2) m_target_method_name, or (3) m_request_context_params parameters.
0
Attacker Value
Unknown

CVE-2008-0578

Disclosure Date: February 05, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the web management login page in Tripwire Enterprise 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown

CVE-2004-0536

Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.
0
Attacker Value
Unknown

CVE-2001-0774

Disclosure Date: October 18, 2001 (last updated February 22, 2025)
Tripwire 1.3.1, 2.2.1 and 2.3.0 allows local users to overwrite arbitrary files and possible gain privileges via a symbolic link attack on temporary files.
0
Attacker Value
Unknown

CVE-1999-0464

Disclosure Date: January 04, 1999 (last updated February 22, 2025)
Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.
0