CVE-2010-3322
- EPSS 0.57%
- Veröffentlicht 14.09.2010 17:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
The XML parser in Splunk 4.0.0 through 4.1.4 allows remote authenticated users to obtain sensitive information and gain privileges via an XML External Entity (XXE) attack to unknown vectors.
CVE-2010-3323
- EPSS 0.39%
- Veröffentlicht 14.09.2010 17:00:02
- Zuletzt bearbeitet 11.04.2025 00:51:21
Splunk 4.0.0 through 4.1.4 allows remote attackers to conduct session hijacking attacks and obtain the splunkd session key via vectors related to the SPLUNKD_SESSION_KEY parameter.
CVE-2010-2502
- EPSS 0.26%
- Veröffentlicht 28.06.2010 18:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple directory traversal vulnerabilities in Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allow (1) remote attackers to read arbitrary files, aka SPL-31194; (2) remote authenticated users to modify arbitrary files, aka SPL-31063; or (3) have an...
CVE-2010-2503
- EPSS 0.26%
- Veröffentlicht 28.06.2010 18:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Multiple cross-site scripting (XSS) vulnerabilities in Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allow remote attackers to inject arbitrary web script or HTML via (1) redirects, aka SPL-31067; (2) unspecified "user->user or user->admin" vectors...
- EPSS 0.37%
- Veröffentlicht 28.06.2010 18:30:00
- Zuletzt bearbeitet 11.04.2025 00:51:21
Splunk 4.0 through 4.0.10 and 4.1 through 4.1.1 allows remote authenticated users to obtain sensitive information via HTTP header injection, aka SPL-31066.
CVE-2010-2429
- EPSS 0.28%
- Veröffentlicht 24.06.2010 12:17:45
- Zuletzt bearbeitet 11.04.2025 00:51:21
Cross-site scripting (XSS) vulnerability in Splunk 4.0 through 4.1.2, when Internet Explorer is used, allows remote attackers to inject arbitrary web script or HTML via the HTTP Referer in a "404 Not Found" response.