Tim van Dijen
8 exploits
Active since Nov 2023
SimpleSAMLphp casserver < 7.0.3 - CAS Ticket Path Traversal
CVSS 8.6
SimpleSAMLphp CAS Server <6.3.1 and <7.0.0 Logout - Open Redirect
CVSS 6.1
SimpleSAMLphp saml2 < 4.17.0 and 5.0.0-alpha.1-5.0.0-alpha.20 - Signature Confusion Attack via HTTPRedirect Binding
CVSS 8.6
xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
CVSS 8.2
xml-security is Missing AES-GCM Authentication Tag Validation on Encrypted Nodes Allows for Unauthorized Decryption
CVSS 8.2
simplesamlphp/saml2 5.0.0-alpha.12 - Insufficient Verification of Data Authenticity in XML Signature Validation
CVSS 6.8
simplesamlphp/xml-common < 1.20.0 - XML External Entity Injection
SimpleSAMLphp saml2 < 4.6.14 and 5.0.0-alpha.1-5.0.0-alpha.18 - XML External Entity Injection
CVSS 8.3