Vulnerabilities > Hypersilence > Silentum Loginsys > 1.0.0

DATE CVE VULNERABILITY TITLE RISK
2009-04-28 CVE-2008-6764 Cross-Site Scripting vulnerability in Hypersilence Silentum Loginsys 1.0.0
Cross-site scripting (XSS) vulnerability in login.php in Silentum LoginSys 1.0.0 allows remote attackers to inject arbitrary web script or HTML via the message parameter.
4.3
2009-04-28 CVE-2008-6763 Improper Authentication vulnerability in Hypersilence Silentum Loginsys 1.0.0
login2.php in Silentum LoginSys 1.0.0 allows remote attackers to bypass authentication and obtain access to an arbitrary account by setting the logged_in cookie to that account's username.
network
low complexity
hypersilence CWE-287
7.5