Vulnerabilities > Navarino

DATE CVE VULNERABILITY TITLE RISK
2018-07-24 CVE-2018-5386 Information Exposure vulnerability in Navarino Infinity 2.2
Some Navarino Infinity functions, up to version 2.2, placed in the URL can bypass any authentication mechanism leading to an information leak.
network
low complexity
navarino CWE-200
7.5
2018-07-24 CVE-2018-5385 Session Fixation vulnerability in Navarino Infinity 2.2
Navarino Infinity is prone to session fixation attacks.
network
low complexity
navarino CWE-384
8.8
2018-07-24 CVE-2018-5384 SQL Injection vulnerability in Navarino Infinity 2.2
Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection.
network
low complexity
navarino CWE-89
critical
9.8