VYPR

Silentum Loginsys

by Hypersilence

CVEs (2)

  • CVE-2008-6764Apr 28, 2009
    risk 0.03cvss epss 0.00

    Cross-site scripting (XSS) vulnerability in login.php in Silentum LoginSys 1.0.0 allows remote attackers to inject arbitrary web script or HTML via the message parameter.

  • CVE-2008-6763Apr 28, 2009
    risk 0.03cvss epss 0.02

    login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's username.