VYPR

OpenPNE

by OpenPNE

CVEs (2)

  • CVE-2013-5350Jan 24, 2014
    risk 0.00cvss epss 0.02

    The "Remember me" feature in the opSecurityUser::getRememberLoginCookie function in lib/user/opSecurityUser.class.php in OpenPNE 3.6.13 before 3.6.13.1 and 3.8.9 before 3.8.9.1 does not properly validate login data in HTTP Cookie headers, which allows remote attackers to conduct…

  • CVE-2010-1040Mar 23, 2010
    risk 0.00cvss epss 0.01

    The "IP address range limitation" function in OpenPNE 1.6 through 1.8, 2.0 through 2.8, 2.10 through 2.14, and 3.0 through 3.4, when mobile device support is enabled, allows remote attackers to bypass the "simple login" functionality via unknown vectors related to spoofing.