Filtered by vendor Secureauth Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2021-31800 2 Fedoraproject, Secureauth 2 Fedora, Impacket 2024-11-21 9.8 Critical
Multiple path traversal vulnerabilities exist in smbserver.py in Impacket through 0.9.22. An attacker that connects to a running smbserver instance can list and write to arbitrary files via ../ directory traversal. This could potentially be abused to achieve arbitrary code execution by replacing /etc/shadow or an SSH authorized key.
CVE-2020-9437 1 Secureauth 1 Secureauth Identity Provider 2024-11-21 4.8 Medium
SecureAuth.aspx in SecureAuth IdP 9.3.0 suffers from a client-side template injection that allows for script execution, in the same manner as XSS.