Skip to main content

Vendor/product archive

patterninsight / pattern_insight CVEs

Beta · best-effort

5 CVEs tagged to patterninsight / pattern_insight0 Critical, 0 High, 4 Medium, 1 Low, 0 Unrated.

CVE-2012-4950

Published Nov 18, 2012

Cross-site scripting (XSS) vulnerability in the Keyword Search page in the web interface in Pattern Insight 2.3 allows remote attackers to inject arbitrary web script or HTML via…

CVSS 4.3 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4938

Published Nov 18, 2012

Cross-site scripting (XSS) vulnerability in the web interface in Pattern Insight 2.3 allows remote authenticated administrators to inject arbitrary web script or HTML via the bann…

CVSS 3.5 · Low
Vendor/product tagsBeta · best-effort

CVE-2012-4937

Published Nov 18, 2012

Session fixation vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack web sessions via a jsession_id cookie.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4936

Published Nov 18, 2012

The web interface in Pattern Insight 2.3 allows remote attackers to conduct clickjacking attacks via a FRAME element.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort

CVE-2012-4935

Published Nov 18, 2012

Cross-site request forgery (CSRF) vulnerability in the web interface in Pattern Insight 2.3 allows remote attackers to hijack the authentication of arbitrary users.

CVSS 6.8 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-5 of 5 CVEsPage 1 of 1