Vulnerabilities > Skyboxsecurity

DATE CVE VULNERABILITY TITLE RISK
2018-01-12 CVE-2015-9250 Path Traversal vulnerability in Skyboxsecurity Skybox Platform
An issue was discovered in Skybox Platform before 7.5.201.
network
low complexity
skyboxsecurity CWE-22
5.0
2018-01-12 CVE-2015-9249 SQL Injection vulnerability in Skyboxsecurity Skybox Platform
An issue was discovered in Skybox Platform before 7.5.201.
network
low complexity
skyboxsecurity CWE-89
7.5
2018-01-12 CVE-2015-9248 Cross-site Scripting vulnerability in Skyboxsecurity Skybox Platform
An issue was discovered in Skybox Platform before 7.5.201.
3.5
2018-01-12 CVE-2015-9247 Cross-site Scripting vulnerability in Skyboxsecurity Skybox Platform 7.5.201
An issue was discovered in Skybox Platform before 7.5.401.
3.5
2018-01-12 CVE-2015-9246 Improper Input Validation vulnerability in Skyboxsecurity Skybox Platform
An issue was discovered in Skybox Platform before 7.5.201.
network
low complexity
skyboxsecurity CWE-20
critical
10.0
2017-10-03 CVE-2017-14773 Unspecified vulnerability in Skyboxsecurity Skybox Manager Client Application 8.5.500
Skybox Manager Client Application prior to 8.5.501 is prone to an elevation of privileges vulnerability during authentication of a valid user in a debugger-pause state.
local
low complexity
skyboxsecurity
4.6
2017-10-03 CVE-2017-14772 Information Exposure vulnerability in Skyboxsecurity Skybox Manager Client Application
Skybox Manager Client Application is prone to information disclosure via a username enumeration attack.
local
low complexity
skyboxsecurity CWE-200
2.1
2017-10-03 CVE-2017-14771 Improper Input Validation vulnerability in Skyboxsecurity Skybox Manager Client Application 8.5.500
Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-supplied files path when uploading files via the application.
local
low complexity
skyboxsecurity CWE-20
3.6
2017-10-03 CVE-2017-14770 Information Exposure vulnerability in Skyboxsecurity Skybox Manager Client Application 8.5.500
Skybox Manager Client Application prior to 8.5.501 is prone to an information disclosure vulnerability of user password hashes.
local
low complexity
skyboxsecurity CWE-200
2.1
2014-05-17 CVE-2014-2084 Permissions, Privileges, and Access Controls vulnerability in Skyboxsecurity Skybox View Appliance and Skybox View Appliance ISO
Skybox View Appliances with ISO 6.3.33-2.14, 6.3.31-2.14, 6.4.42-2.54, 6.4.45-2.56, and 6.4.46-2.57 does not properly restrict access to the Admin interface, which allows remote attackers to obtain sensitive information via a request to (1) scripts/commands/getSystemInformation or (2) scripts/commands/getNetworkConfigurationInfo, cause a denial of service (reboot) via a request to scripts/commands/reboot, or cause a denial of service (shutdown) via a request to scripts/commands/shutdown.
network
low complexity
skyboxsecurity CWE-264
8.5