Логотип exploitDog
bind:CVE-2013-4962
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2013-4962

Количество 4

Количество 4

ubuntu логотип

CVE-2013-4962

больше 12 лет назад

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

CVSS2: 5.8
EPSS: Низкий
nvd логотип

CVE-2013-4962

больше 12 лет назад

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

CVSS2: 5.8
EPSS: Низкий
debian логотип

CVE-2013-4962

больше 12 лет назад

The reset password page in Puppet Enterprise before 3.0.1 does not for ...

CVSS2: 5.8
EPSS: Низкий
github логотип

GHSA-g2xg-vq5p-8wvv

больше 3 лет назад

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
ubuntu логотип
CVE-2013-4962

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

CVSS2: 5.8
0%
Низкий
больше 12 лет назад
nvd логотип
CVE-2013-4962

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

CVSS2: 5.8
0%
Низкий
больше 12 лет назад
debian логотип
CVE-2013-4962

The reset password page in Puppet Enterprise before 3.0.1 does not for ...

CVSS2: 5.8
0%
Низкий
больше 12 лет назад
github логотип
GHSA-g2xg-vq5p-8wvv

The reset password page in Puppet Enterprise before 3.0.1 does not force entry of the current password, which allows attackers to modify user passwords by leveraging session hijacking, an unattended workstation, or other vectors.

0%
Низкий
больше 3 лет назад

Уязвимостей на страницу