Gosa Project Gosa vulnerabilities
6 known vulnerabilities affecting gosa_project/gosa.
Total CVEs
6
CISA KEV
0
Public exploits
0
Exploited in wild
0
Severity breakdown
CRITICAL3MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2019-14466MEDIUMCVSS 6.5v2.7.5.22019-12-31
CVE-2019-14466 [MEDIUM] CWE-502 CVE-2019-14466: The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, wh
The GOsa_Filter_Settings cookie in GONICUS GOsa 2.7.5.2 is vulnerable to PHP objection injection, which allows a remote authenticated attacker to perform file deletions (in the context of the user account that runs the web server) via a crafted cookie value, because unserialize is used to restore filter settings from a cookie.
nvdosv
CVE-2019-11187CRITICALCVSS 9.8≥ 0, < 2.7.4+reloaded3-92019-08-15
CVE-2019-11187 [CRITICAL] CVE-2019-11187: Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing th
Incorrect Access Control in the LDAP class of GONICUS GOsa through 2019-04-11 allows an attacker to log into any account with a username containing the case-insensitive substring "success" when an arbitrary password is provided.
osv
CVE-2018-1000528MEDIUMCVSS 6.1≥ 0, < 2.7.4+reloaded3-52018-06-26
CVE-2018-1000528 [MEDIUM] CVE-2018-1000528: GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password for
GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password form (html/password.php, #308) that can result in injection of arbitrary web script or HTML. This attack appear to be exploitable via the victim must open a s
osv
CVE-2015-8771CRITICALCVSS 9.8≥ 0, < 2.7.4+reloaded2-62017-02-13
CVE-2015-8771 [CRITICAL] CVE-2015-8771: The generate_smb_nt_hash function in include/functions
The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password.
osv
CVE-2014-9760MEDIUMCVSS 6.1≥ 0, < 2.7.4+reloaded1-52017-02-13
CVE-2014-9760 [MEDIUM] CVE-2014-9760: Cross-site scripting (XSS) vulnerability in the displayLogin function in html/index
Cross-site scripting (XSS) vulnerability in the displayLogin function in html/index.php in GOsa allows remote attackers to inject arbitrary web script or HTML via the username.
osv
CVE-2007-0313CRITICALCVSS 9.0≥ 0, < 2.5.8-12007-01-18
CVE-2007-0313 [CRITICAL] CVE-2007-0313: Unspecified vulnerability in GONICUS System Administration (GOsa) before 2
Unspecified vulnerability in GONICUS System Administration (GOsa) before 2.5.8 allows remote authenticated users to modify certain settings, including the admin password, via crafted POST requests.
osv