VendorsXceediumxsuite2.3.0
Vulnerabilities

Xceedium Xsuite 2.3.0

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2015-4664
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
Published 2018-06-18 · Modified
9.81 PoCEPSS 0.206
CVE-2015-4667
Multiple hardcoded credentials in Xsuite 2.x.
Published 2017-09-25 · Modified
9.81 PoCEPSS 0.111
CVE-2015-4669
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.
Published 2017-09-25 · Modified
7.81 PoCEPSS 0.011
CVE-2015-4668
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.
Published 2017-09-25 · Modified
6.11 PoCEPSS 0.067
CVE-2015-4666
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.
Published 2015-08-13 · Modified
5.01 PoCEPSS 0.162
CVE-2015-4665
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName parameter.
Published 2015-08-13 · Modified
4.31 PoCEPSS 0.033