Xceedium Xsuite vulnerabilities
5 known vulnerabilities affecting xceedium/xsuite.
Total CVEs
5
CISA KEV
0
Public exploits
5
Exploited in wild
0
Severity breakdown
CRITICAL1HIGH1MEDIUM3
Vulnerabilities
Page 1 of 1
CVE-2015-4664CRITICALCVSS 9.8PoCv2.3.0v2.4.3.02018-06-18
CVE-2015-4664 [CRITICAL] CWE-20 CVE-2015-4664: An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allow
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
nvd
CVE-2015-4669HIGHCVSS 7.8PoCv2.3.0v2.4.3.02017-09-25
CVE-2015-4669 [HIGH] CWE-89 CVE-2015-4669: The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.
nvd
CVE-2015-4668MEDIUMCVSS 6.1PoCv2.3.0v2.4.3.02017-09-25
CVE-2015-4668 [MEDIUM] CWE-601 CVE-2015-4668: Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.
nvd
CVE-2015-4665MEDIUMCVSS 4.3PoCv2.3.0v2.4.3.02015-08-13
CVE-2015-4665 [MEDIUM] CWE-79 CVE-2015-4665: Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allo
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName parameter.
nvd
CVE-2015-4666MEDIUMCVSS 5.0PoCv2.3.0v2.4.3.02015-08-13
CVE-2015-4666 [MEDIUM] CWE-22 CVE-2015-4666: Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.
nvd