VYPR

gosa-core

by gosa-project

Source repositories

CVEs (2)

  • CVE-2015-8771CriFeb 13, 2017
    risk 0.57cvss 9.8epss 0.02

    The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password.

  • CVE-2014-9760MedFeb 13, 2017
    risk 0.33cvss 6.1epss 0.01

    Cross-site scripting (XSS) vulnerability in the displayLogin function in html/index.php in GOsa allows remote attackers to inject arbitrary web script or HTML via the username.