Show filters
6 Total Results
Displaying 1-6 of 6
Sort by:
Attacker Value
Unknown
CVE-2015-6237
Disclosure Date: December 27, 2017 (last updated November 26, 2024)
The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP filter restrictions via crafted "privileged commands."
0
Attacker Value
Unknown
CVE-2013-5005
Disclosure Date: January 29, 2014 (last updated October 05, 2023)
Multiple cross-site scripting (XSS) vulnerabilities in ajaxRequest/methodCall.do in Tripwire Enterprise 8.2 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) m_target_class_name, (2) m_target_method_name, or (3) m_request_context_params parameters.
0
Attacker Value
Unknown
CVE-2008-0578
Disclosure Date: February 05, 2008 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the web management login page in Tripwire Enterprise 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
0
Attacker Value
Unknown
CVE-2004-0536
Disclosure Date: August 06, 2004 (last updated February 22, 2025)
Format string vulnerability in Tripwire commercial 4.0.1 and earlier, including 2.4, and open source 2.3.1 and earlier, allows local users to gain privileges via format string specifiers in a file name, which is used in the generation of an email report.
0
Attacker Value
Unknown
CVE-2001-0774
Disclosure Date: October 18, 2001 (last updated February 22, 2025)
Tripwire 1.3.1, 2.2.1 and 2.3.0 allows local users to overwrite arbitrary files and possible gain privileges via a symbolic link attack on temporary files.
0
Attacker Value
Unknown
CVE-1999-0464
Disclosure Date: January 04, 1999 (last updated February 22, 2025)
Local users can perform a denial of service in Tripwire 1.2 and earlier using long filenames.
0