modzero

6 exploits Active since Aug 2015
CVE-2015-4668 EXPLOITDB MEDIUM text WRITEUP
Xceedium Xsuite - Open Redirect via redirurl Parameter
Open redirect vulnerability in Xsuite 2.4.4.5 and earlier allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the redirurl parameter.
CVSS 6.1
CVE-2015-4667 EXPLOITDB CRITICAL text WRITEUP
Xceedium Xsuite 2.x - Use of Hard-coded Credentials
Multiple hardcoded credentials in Xsuite 2.x.
CVSS 9.8
CVE-2015-4666 EXPLOITDB text WRITEUP
Xceedium Xsuite - Directory Traversal via opm/read_sessionlog.php logFile Parameter
Directory traversal vulnerability in opm/read_sessionlog.php in Xceedium Xsuite 2.4.4.5 and earlier allows remote attackers to read arbitrary files via a ....// (quadruple dot double slash) in the logFile parameter.
CVE-2015-4665 EXPLOITDB text WRITEUP
Xceedium Xsuite <= 2.4.4.1 - Cross-Site Scripting via ajax_cmd.php fileName Parameter
Cross-site scripting (XSS) vulnerability in ajax_cmd.php in Xceedium Xsuite 2.4.4.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the fileName parameter.
CVE-2015-4664 EXPLOITDB CRITICAL text WRITEUP
CA Privileged Access Manager < 2.4.4.4 - Remote Command Execution
An improper input validation vulnerability in CA Privileged Access Manager 2.4.4.4 and earlier allows remote attackers to execute arbitrary commands.
CVSS 9.8
CVE-2015-4669 EXPLOITDB HIGH text WRITEUP
Xceedium Xsuite 2.x - Unauthenticated SQL Injection via Default MySQL Root Account
The MySQL "root" user in Xsuite 2.x does not have a password set, which allows local users to access databases on the system.
CVSS 7.8