Vulnerabilities > Cogentdatahub > Cogent Datahub > 7.3.0

DATE CVE VULNERABILITY TITLE RISK
2016-03-29 CVE-2016-2288 Permissions, Privileges, and Access Controls vulnerability in Cogentdatahub Cogent Datahub
Cogent DataHub before 7.3.10 allows local users to gain privileges by leveraging the user or guest role to modify a file.
local
low complexity
cogentdatahub CWE-264
7.2
2014-05-30 CVE-2014-2354 Credentials Management vulnerability in Cogentdatahub Cogent Datahub
Cogent DataHub before 7.3.5 does not use a salt during password hashing, which makes it easier for context-dependent attackers to obtain cleartext passwords via a brute-force attack.
network
low complexity
cogentdatahub CWE-255
5.0
2014-05-30 CVE-2014-2353 Cross-Site Scripting vulnerability in Cogentdatahub Cogent Datahub
Cross-site scripting (XSS) vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3
2014-05-30 CVE-2014-2352 Path Traversal vulnerability in Cogentdatahub Cogent Datahub
Directory traversal vulnerability in Cogent DataHub before 7.3.5 allows remote attackers to read arbitrary files of unspecified types, or cause a web-server denial of service, via a crafted pathname.
network
low complexity
cogentdatahub CWE-22
6.4
2014-05-22 CVE-2014-3789 Code Injection vulnerability in Cogentdatahub Cogent Datahub
GetPermissions.asp in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary commands via unspecified vectors.
network
low complexity
cogentdatahub CWE-94
7.5
2014-05-22 CVE-2014-3788 Improper Restriction of Operations Within the Bounds of A Memory Buffer vulnerability in Cogentdatahub Cogent Datahub
Heap-based buffer overflow in the Web Server in Cogent Real-Time Systems Cogent DataHub before 7.3.5 allows remote attackers to execute arbitrary code via a negative value in the Content-Length field in a request.
network
low complexity
cogentdatahub CWE-119
7.5