VYPR

Xsuite

by Xceedium

CVEs (5)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2015-4667Cri0.699.80.24Sep 25, 2017Multiple hardcoded credentials in Xsuite 2.x.
CVE-2015-4669Hig0.547.80.00Sep 25, 2017The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.
CVE-2015-4668Med0.436.10.04Sep 25, 2017Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.
CVE-2015-46660.040.16Aug 13, 2015Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.
CVE-2015-46650.030.03Aug 13, 2015Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName parameter.