Vulnerabilities > Packetfence

DATE CVE VULNERABILITY TITLE RISK
2018-02-01 CVE-2011-4069 LDAP Injection vulnerability in Packetfence
html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to conduct LDAP injection attacks and consequently bypass authentication via a crafted username.
network
low complexity
packetfence CWE-90
7.5
2018-02-01 CVE-2011-4068 Improper Authentication vulnerability in Packetfence
The check_password function in html/admin/login.php in PacketFence before 3.0.2 allows remote attackers to bypass authentication via an empty password.
network
low complexity
packetfence CWE-287
7.5
2012-08-31 CVE-2012-4742 Remote Security vulnerability in Packetfence
The web_node_register function in web.pm in PacketFence before 3.0.2 might allow remote attackers to execute arbitrary code via unspecified vectors.
network
low complexity
packetfence
7.5
2012-08-31 CVE-2012-4741 Improper Authentication vulnerability in Packetfence
The RADIUS extension in PacketFence before 3.3.0 uses a different user name than is used for authentication for users with custom VLAN assignment extensions, which allows remote attackers to spoof user identities via the User-Name RADIUS attribute.
network
low complexity
packetfence CWE-287
5.0
2012-08-31 CVE-2012-4740 Cross-Site Scripting vulnerability in Packetfence
Cross-site scripting (XSS) vulnerability in the captive portal in PacketFence before 3.3.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
4.3