Anfälligkeitssuche        Suche in 219043 CVE Beschreibungen
und 99761 Test Beschreibungen,
Zugriff auf 10,000+ Quellverweise.
Tests   CVE   Alle  

Test Kennung:1.3.6.1.4.1.25623.1.0.805269
Kategorie:Web application abuses
Titel:Novell eDirectory iMonitor Multiple Vulnerabilities - Feb15
Zusammenfassung:This host is installed with Novell eDirectory; and is prone to multiple vulnerabilities.
Beschreibung:Summary:
This host is installed with Novell eDirectory
and is prone to multiple vulnerabilities.

Vulnerability Insight:
Multiple errors exist due to:

- Improper sanitization by the /nds/search/data script when input is passed
via the 'rdn' parameter.

- An error in the /nds/files/opt/novell/eDirectory/lib64/ndsimon/public/images.

Vulnerability Impact:
Successful exploitation will allow attackers
to execute arbitrary script code in a user's browser session within the trust
relationship between their browser and the server, and disclose virtual memory
including passwords.

Affected Software/OS:
Novell eDirectory versions prior to 8.8 SP8
Patch 4.

Solution:
Upgrade to Novell eDirectory version 8.8 SP8
Patch 4 or later.

CVSS Score:
4.3

CVSS Vector:
AV:N/AC:M/Au:N/C:N/I:P/A:N

Querverweis: BugTraq ID: 71741
BugTraq ID: 71748
Common Vulnerability Exposure (CVE) ID: CVE-2014-5212
Bugtraq: 20141219 SEC Consult SA-20141219-0 :: XSS & Memory Disclosure vulnerabilities in NetIQ eDirectory NDS iMonitor (Google Search)
http://www.securityfocus.com/archive/1/534284
https://www.sec-consult.com/fxdata/seccons/prod/temedia/advisories_txt/20141219-0_NetIQ_eDirectory_iMonitor_XSS_Memory_Disclosure_v10.txt
http://www.securitytracker.com/id/1031408
Common Vulnerability Exposure (CVE) ID: CVE-2014-5213
CopyrightCopyright (C) 2015 Greenbone Networks GmbH

Dies ist nur einer von 99761 Anfälligkeitstests in unserem Testpaket. Finden Sie mehr über unsere vollständigen Sicherheitsüberprüfungen heraus.

Um einen gratis Test für diese Anfälligkeit auf Ihrem System durchlaufen zu lassen, registrieren Sie sich bitte unten.




© 1998-2024 E-Soft Inc. Alle Rechte vorbehalten.