VYPR

Xsuite

by Xceedium

CVEs (5)

  • CVE-2015-4667CriSep 25, 2017
    risk 0.68cvss 9.8epss 0.11

    Multiple hardcoded credentials in Xsuite 2.x.

  • CVE-2015-4669HigSep 25, 2017
    risk 0.54cvss 7.8epss 0.01

    The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.

  • CVE-2015-4668MedSep 25, 2017
    risk 0.43cvss 6.1epss 0.07

    Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.

  • CVE-2015-4666Aug 13, 2015
    risk 0.04cvss epss 0.16

    Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.

  • CVE-2015-4665Aug 13, 2015
    risk 0.03cvss epss 0.03

    Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName parameter.