Логотип exploitDog
bind:CVE-2021-37935
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2021-37935

Количество 2

Количество 2

nvd логотип

CVE-2021-37935

около 4 лет назад

An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.

CVSS3: 7.5
EPSS: Низкий
github логотип

GHSA-xv5r-jf97-8xjm

около 4 лет назад

An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2021-37935

An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.

CVSS3: 7.5
0%
Низкий
около 4 лет назад
github логотип
GHSA-xv5r-jf97-8xjm

An information disclosure vulnerability in the login page of Huntflow Enterprise before 3.10.4 could allow an unauthenticated, remote user to get information about the domain name of the configured LDAP server. An attacker could exploit this vulnerability by requesting the login page and searching for the "isLdap" JavaScript parameter in the HTML source code.

0%
Низкий
около 4 лет назад

Уязвимостей на страницу