
CVE-2016-4857
https://notcve.org/view.php?id=CVE-2016-4857
12 May 2017 — Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.2, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.11 and Splunk Light prior to 6.4.2 allows to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Vulnerabilidad de redirección abierta en Splunk Enterprise versiones 6.4.x anteriores a la 6.4.2, Splunk Enterprise versiones 6.3.x anteriores a la 6.3.6, Splunk Enterprise versiones 6.2.x anteriores a la 6.2.11 y Splunk Light ... • https://jvn.jp/en/jp/JVN39926655/index.html • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2016-4858
https://notcve.org/view.php?id=CVE-2016-4858
12 May 2017 — Cross-site scripting vulnerability in Splunk Enterprise 6.4.x prior to 6.4.2, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.10, Splunk Enterprise 6.1.x prior to 6.1.11, Splunk Enterprise 6.0.x prior to 6.0.12, Splunk Enterprise 5.0.x prior to 5.0.16 and Splunk Light prior to 6.4.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de Cross-site scripting en Splunk Enterprise versiones 6.4.x anteriores a la 6.4.2, Splunk Enter... • https://jvn.jp/en/jp/JVN71462075/index.html • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2016-4859
https://notcve.org/view.php?id=CVE-2016-4859
12 May 2017 — Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.3, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.10, Splunk Enterprise 6.1.x prior to 6.1.11, Splunk Enterprise 6.0.x prior to 6.0.12, Splunk Enterprise 5.0.x prior to 5.0.16 and Splunk Light prior to 6.4.3 allows to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors. Vulnerabilidad de redirección abierta en Splunk Enterprise versiones 6.4.x anteriores a la 6.4.3, Splunk... • http://www.securityfocus.com/bid/92603 • CWE-601: URL Redirection to Untrusted Site ('Open Redirect') •

CVE-2017-5607 – Splunk Enterprise - Information Disclosure
https://notcve.org/view.php?id=CVE-2017-5607
01 Apr 2017 — Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage. Splunk Enterprise 5.0.x en versiones anteriores a 5.0.18, 6.0.x en versiones anteriores a 6.0.14, 6.1.x en versiones anteriore... • https://packetstorm.news/files/id/141875 • CWE-200: Exposure of Sensitive Information to an Unauthorized Actor •

CVE-2017-5880
https://notcve.org/view.php?id=CVE-2017-5880
04 Feb 2017 — Splunk Web in Splunk Enterprise versions 6.5.x before 6.5.2, 6.4.x before 6.4.5, 6.3.x before 6.3.9, 6.2.x before 6.2.13, 6.1.x before 6.1.12, 6.0.x before 6.0.13, 5.0.x before 5.0.17 and Splunk Light versions before 6.5.2 allows remote authenticated users to cause a denial of service (daemon crash) via a crafted GET request, aka SPL-130279. Splunk Web en Splunk Enterprise versiones 6.5.x en versiones anteriores a 6.5.2, 6.4.x en versiones anteriores a 6.4.5, 6.3.x en versiones anteriores a 6.3.9, 6.2.x en ... • http://www.splunk.com/view/SP-CAAAPW8 • CWE-20: Improper Input Validation •

CVE-2014-3147
https://notcve.org/view.php?id=CVE-2014-3147
10 Oct 2014 — Cross-site scripting (XSS) vulnerability in the auto-complete feature in Splunk Enterprise before 6.0.4 allows remote authenticated users to inject arbitrary web script or HTML via a CSV file. Vulnerabilidad de XSS en la caracteristica de autocompletado en Splunk Enterprise anterior a 6.0.4 permite a usuarios remotos autenticados inyectar secuencias de comandos web o HTML arbitrarios a través de un fichero CSV. • http://securitytracker.com/id?1030800 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-7394
https://notcve.org/view.php?id=CVE-2013-7394
07 Aug 2014 — The "runshellscript echo.sh" script in Splunk before 5.0.5 allows remote authenticated users to execute arbitrary commands via a crafted string. NOTE: this issue was SPLIT from CVE-2013-6771 per ADT2 due to different vulnerability types. La secuencia de comandos 'runshellscript echo.sh' en Splunk anterior a 5.0.5 permite a usuarios remotos autenticados ejecutar código arbitrario a través de una cadena manipulada. NOTE: este problema fue dividido (SPLIT) del CVE-2013-6771 por ADT2 debido a tipos de vulnerabi... • http://www.splunk.com/view/SP-CAAAH76 • CWE-94: Improper Control of Generation of Code ('Code Injection') •

CVE-2013-6771 – Splunk runshellscript echo.sh Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2013-6771
03 Apr 2014 — Directory traversal vulnerability in the collect script in Splunk before 5.0.5 allows remote attackers to execute arbitrary commands via a .. (dot dot) in the file parameter. NOTE: this issue was SPLIT per ADT2 due to different vulnerability types. CVE-2013-7394 is for the issue in the "runshellscript echo.sh" script. Vulnerabilidad de salto de directorio en la secuencia de comandos collect en Splunk anterior a 5.0.5 permite a atacantes remotos ejecutar comandos arbitrarios a través de un .. • http://www.splunk.com/view/SP-CAAAH76 • CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') •

CVE-2014-2578
https://notcve.org/view.php?id=CVE-2014-2578
02 Apr 2014 — Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk before 5.0.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en Splunk Web en Splunk anterior a 5.0.8 permite a atacantes remotos inyectar script Web o HTML arbitrarios a través de vectores no especificados. • http://secunia.com/advisories/57554 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •

CVE-2013-6870
https://notcve.org/view.php?id=CVE-2013-6870
25 Nov 2013 — Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk before 5.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. Vulnerabilidad de XSS en Splunk Web de Splunk anterior a la versión 5.0.6 permite a atacantes remotos inyectar script web o HTML arbitrario a través de vectores sin especificar. • http://secunia.com/advisories/55774 • CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') •