Vulnerabilities > Checkpoint > Connectra NGX > r62

DATE CVE VULNERABILITY TITLE RISK
2009-01-28 CVE-2008-5994 Cross-Site Scripting vulnerability in Checkpoint Connectra NGX R62
Cross-site scripting (XSS) vulnerability in index.php in Check Point Connectra NGX R62 HFA_01 allows remote attackers to inject arbitrary web script or HTML via the dir parameter.
network
checkpoint CWE-79
4.3
2007-01-24 CVE-2007-0471 Permissions, Privileges, and Access Controls vulnerability in Checkpoint Connectra NGX R60/R62
sre/params.php in the Integrity Clientless Security (ICS) component in Check Point Connectra NGX R62 3.x and earlier before Security Hotfix 5, and possibly VPN-1 NGX R62, allows remote attackers to bypass security requirements via a crafted Report parameter, which returns a valid ICSCookie authentication token.
network
low complexity
checkpoint CWE-264
7.5