Skip to main content

Vendor/product archive

apereo / phpcas CVEs

Beta · best-effort

9 CVEs tagged to apereo / phpcas1 Critical, 2 High, 5 Medium, 1 Low, 0 Unrated.

CVE-2017-1000071

Published Jul 17, 2017

Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2012-5583

Published Jun 6, 2014

phpCAS before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows…

CVSS 5.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3692

Published Oct 7, 2010

Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create or overwrite arbitra…

CVSS 6.4 · Medium
Vendor/product tagsBeta · best-effort

CVE-2010-3691

Published Oct 7, 2010

PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to overwrite arbitrary files via a symlink attack on an unspecified file.

CVSS 3.3 · Low
Vendor/product tagsBeta · best-effort

CVE-2010-3690

Published Oct 7, 2010

Multiple cross-site scripting (XSS) vulnerabilities in phpCAS before 1.1.3, when proxy mode is enabled, allow remote attackers to inject arbitrary web script or HTML via (1) a cra…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-9 of 9 CVEsPage 1 of 1