CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
104409 | CVE-2017-7589 | Candidate | In OpenIDM through 4.0.0 before 4.5.0, the info endpoint may leak sensitive information upon a request by the "anonymous" user, as demonstrated by responses with a 200 HTTP status code and a JSON object containing IP address strings. This is related to a missing access-control check in bin/defaults/script/info/login.js. | Assigned (20170408) | None (candidate not yet proposed) | View | |
104410 | CVE-2017-7590 | Candidate | OpenIDM through 4.0.0 and 4.5.0 is vulnerable to persistent cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by a crafted Managed Object Name. | Assigned (20170408) | None (candidate not yet proposed) | View | |
104411 | CVE-2017-7591 | Candidate | OpenIDM through 4.0.0 and 4.5.0 is vulnerable to reflected cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by the _sortKeys parameter to the authzRoles script under managed/user/. | Assigned (20170408) | None (candidate not yet proposed) | View | |
30116 | CVE-2007-6759 | Candidate | Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCRABBIT cookie. | Assigned (20170407) | None (candidate not yet proposed) | View | |
30117 | CVE-2007-6760 | Candidate | Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCCOOKIE cookie. | Assigned (20170407) | None (candidate not yet proposed) | View |
Page 643 of 20943, showing 5 records out of 104715 total, starting on record 3211, ending on 3215