VendorsVDG Securityvdg_sense2.3.13
Vulnerabilities

VDG Security VDG Sense 2.3.13

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2014-9451
Multiple stack-based buffer overflows in the DIVA web service API (/webservice) in VDG Security SENSE (formerly DIVA) 2.3.13 allow remote attackers to execute arbitrary code via the (1) user or (2) password parameter in an AuthenticateUser request.
Published 2015-01-02 · Modified
7.5EPSS 0.046
CVE-2014-9452
Directory traversal vulnerability in VDG Security SENSE (formerly DIVA) 2.3.13 allows remote attackers to read arbitrary files via a .. (dot dot) in the default URI to images/.
Published 2015-01-02 · Modified
5.0EPSS 0.028
CVE-2014-9576
VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !DVService for the (2) postgres and (3) NTP Windows user accounts, which allows remote attackers to obtain access.
Published 2015-01-08 · Modified
5.0EPSS 0.023
CVE-2014-9578
VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers to gain login access by leveraging knowledge of a password hash.
Published 2015-01-08 · Modified
5.0EPSS 0.022
CVE-2014-9579
VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtain sensitive information by reading the plugin configuration files.
Published 2015-01-08 · Modified
5.0EPSS 0.017
CVE-2014-9577
VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain usernames and password hashes by logging in to TCP port 51410 and reading the response.
Published 2015-01-08 · Modified
4.0EPSS 0.018