Vulnerabilities > Splunk > Splunk > 6.1.1

DATE CVE VULNERABILITY TITLE RISK
2017-01-10 CVE-2016-10126 Permissions, Privileges, and Access Controls vulnerability in Splunk
Splunk Web in Splunk Enterprise 5.0.x before 5.0.17, 6.0.x before 6.0.13, 6.1.x before 6.1.12, 6.2.x before 6.2.12, 6.3.x before 6.3.8, and 6.4.x before 6.4.4 allows remote attackers to conduct HTTP request injection attacks and obtain sensitive REST API authentication-token information via unspecified vectors, aka SPL-128840.
network
low complexity
splunk CWE-264
critical
10.0
2015-08-18 CVE-2015-6515 Cross-site Scripting vulnerability in Splunk
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.2.x before 6.2.4, 6.1.x before 6.1.8, 6.0.x before 6.0.9, and 5.0.x before 5.0.13 and Splunk Light 6.2.x before 6.2.4 allows remote attackers to inject arbitrary web script or HTML via a header.
network
splunk CWE-79
4.3
2014-12-16 CVE-2014-5466 Cross-Site Scripting vulnerability in Splunk
Cross-site scripting (XSS) vulnerability in the Dashboard in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4, 6.0.x before 6.0.7, and 5.0.x before 5.0.10 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
splunk CWE-79
4.3
2014-10-21 CVE-2014-8380 Cross-Site Scripting vulnerability in Splunk 6.1.1
Cross-site scripting (XSS) vulnerability in Splunk 6.1.1 allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer Header in a "404 Not Found" response.
network
splunk CWE-79
4.3
2014-10-16 CVE-2014-8303 Cross-Site Scripting vulnerability in Splunk
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4 and 6.0.x before 6.0.6 allows remote attackers to inject arbitrary web script or HTML via vectors related to event parsing.
network
splunk CWE-79
4.3
2014-10-16 CVE-2014-8302 Cross-Site Scripting vulnerability in Splunk
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.4, 6.0.x before 6.0.6, and 5.0.x before 5.0.10 allows remote attackers to inject arbitrary web script or HTML via vectors related to dashboard.
network
splunk CWE-79
3.5
2014-08-12 CVE-2014-5198 Cross-Site Scripting vulnerability in Splunk 6.1/6.1.1/6.1.2
Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.1.x before 6.1.3 allows remote attackers to inject arbitrary web script or HTML via the Referer HTTP header.
network
splunk CWE-79
4.3
2014-08-12 CVE-2014-5197 Path Traversal vulnerability in Splunk 6.1/6.1.1/6.1.2
Directory traversal vulnerability in (1) Splunk Web or the (2) Splunkd HTTP Server in Splunk Enterprise 6.1.x before 6.1.3 allows remote authenticated users to read arbitrary files via a ..
network
low complexity
splunk CWE-22
4.0