Page 2 of 17 results (0.002 seconds)

CVSS: 7.5EPSS: 6%CPEs: 1EXPL: 1

28 Jun 2013 — The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows context-dependent attackers to obtain sensitive information by leveraging the presence of (1) a session ID in the jsessionid field to secsphLogin.jsp or (2) credentials in the j_password parameter to j_acegi_security_check, and reading (a) web-server access logs, (b) web-server Referer logs, or (c) the browser history. SecureSphere Operations Manager (SOM) Management Server en Imperva SecureSphere v9.0.0.5, pe... • https://www.exploit-db.com/exploits/25977 • CWE-255: Credentials Management Errors •

CVSS: 5.3EPSS: 5%CPEs: 1EXPL: 1

28 Jun 2013 — The SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote attackers to obtain sensitive information via (1) a direct request to dwr/call/plaincall/AsyncOperationsContainer.getOperationState.dwr, which reveals the installation path in the s0.filePath field, or (2) a T/keyManagement request to plain/settings.html, which reveals a temporary path in an error message. SecureSphere Operations Manager (SOM) Management Server en Imperva SecureSphere v9.0.0.5, permite ... • https://www.exploit-db.com/exploits/25977 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVSS: 8.8EPSS: 2%CPEs: 1EXPL: 1

28 Jun 2013 — The Key Management feature in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to upload executable files via the (1) private_key or (2) public_key parameter in a T/keyManagement request to plain/settings.html, as demonstrated by uploading a Linux ELF file and a shell script. La funcionalidad Key Management en SecureSphere Operations Manager (SOM) Management Server en Imperva SecureSphere v9.0.0.5 permite a usuarios autenticados re... • https://www.exploit-db.com/exploits/25977 • CWE-20: Improper Input Validation •

CVSS: 8.8EPSS: 3%CPEs: 1EXPL: 1

28 Jun 2013 — plain/actionsets.html in the SecureSphere Operations Manager (SOM) Management Server in Imperva SecureSphere 9.0.0.5 allows remote authenticated users to execute arbitrary commands via a task with a [command].value field in conjunction with an [arguments].value field. plain/actionsets.html en el SecureSphere Operations Manager (SOM) Management Server en Imperva SecureSphere v9.0.0.5 permite a usuarios autenticados remotamente ejecutar comandos a través de una tarea con un campo [command].value en conjunción... • https://www.exploit-db.com/exploits/25977 • CWE-20: Improper Input Validation •

CVSS: 6.1EPSS: 0%CPEs: 7EXPL: 0

06 Jun 2011 — Cross-site scripting (XSS) vulnerability in the management GUI in the MX Management Server in Imperva SecureSphere Web Application Firewall 6.2, 7.x, and 8.x allows remote attackers to inject arbitrary web script or HTML via an HTTP request to a firewalled server, aka Bug ID 31759. Vulnerabilidad de ejecución de secuencias de comandos en sitios cruzados (XSS) en el GUI de control de MX Management Server en Imperva SecureSphere Web Application Firewall v6.2, 7.x, y 8.x , permite a atacantes remotos inyectar ... • http://secunia.com/advisories/44772 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVSS: 9.1EPSS: 0%CPEs: 22EXPL: 0

15 Apr 2010 — Imperva SecureSphere Web Application Firewall and Database Firewall 5.0.0.5082 through 7.0.0.7078 allow remote attackers to bypass intrusion-prevention functionality via a request that has an appended long string containing an unspecified manipulation. Imperva SecureSphere Web Application Firewall y Database Firewall v5.0.0.5082 a la v7.0.0.7078, permite a atacantes remotos evitar la funcionalidad de prevención frente a intrusiones mediante un petición que tiene añadida una cadena larga manipulada de un mod... • http://www.clearskies.net/documents/css-advisory-css1001-imperva.php •

CVSS: 6.1EPSS: 0%CPEs: 3EXPL: 2

24 Mar 2008 — Cross-site scripting (XSS) vulnerability in the management GUI in Imperva SecureSphere MX Management Server 5.0 allows remote attackers to inject arbitrary web script or HTML via an invalid or prohibited request to a web server protected by SecureSphere, which triggers injection into the "corrective action" section of an alert page. Vulnerabilidad de secuencias de comandos en sitios cruzados (XSS) en el GUI de administración de Imperva SecureSphere MX Management Server 5.0 permite a atacantes remotos inyect... • https://www.exploit-db.com/exploits/31413 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •