Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 4

Количество 4

ubuntu логотип

CVE-2013-4962

около 13 лет назад

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2013-4962

около 13 лет назад

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2013-4962

около 13 лет назад

The reset password page in Puppet Enterprise before 3.0.1 does not for ...

CVSS2: 5.8
EPSS: Низкий
github логотип

GHSA-g2xg-vq5p-8wvv

больше 4 лет назад

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2013-4962

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

CVSS2: 5.8
1%
Низкий
около 13 лет назад
nvd логотип
CVE-2013-4962

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

CVSS2: 5.8
1%
Низкий
около 13 лет назад
debian логотип
CVE-2013-4962

The reset password page in Puppet Enterprise before 3.0.1 does not for ...

CVSS2: 5.8
1%
Низкий
около 13 лет назад
github логотип
GHSA-g2xg-vq5p-8wvv

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

1%
Низкий
больше 4 лет назад

Уязвимостей на страницу