Armorlogic
armorlogic
5 CVEs • 1 product
Products (1)
Click to collapseToggle
Products (1)
Click to collapse
CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Armorlogic 1Profense Web Application Firewall Apr 23, 2026 May 21, 2009 N/A· v4 N/A· v3 10.0 HIGH· v2 Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, has a default root password hash, and permits password-based root logins over SSH, which makes it easier for remote attackers to obtain...Show more |
1Armorlogic 1Profense Web Application Firewall Apr 23, 2026 May 21, 2009 N/A· v4 N/A· v3 7.5 HIGH· v2 Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "positive model," which allows remote attackers to bypass certain protection mechanisms via a %0A (encod...Show more |
1Armorlogic 1Profense Web Application Firewall Apr 23, 2026 May 21, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Armorlogic Profense Web Application Firewall before 2.2.22, and 2.4.x before 2.4.4, does not properly implement the "negative model," which allows remote attackers to conduct cross-site scripting (XSS) attacks via a modi...Show more |
1Armorlogic 1Profense Web Application Firewall Apr 23, 2026 Feb 10, 2009 N/A· v4 N/A· v3 6.8 MEDIUM· v2 Multiple cross-site request forgery (CSRF) vulnerabilities in ajax.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allow remote attackers to hijack the authentication of administrators for requests that (1) shu...Show more |
1Armorlogic 1Profense Web Application Firewall Apr 23, 2026 Feb 10, 2009 N/A· v4 N/A· v3 4.3 MEDIUM· v2 Cross-site scripting (XSS) vulnerability in proxy.html in Profense Web Application Firewall 2.6.2 and 2.6.3 allows remote attackers to inject arbitrary web script or HTML via the proxy parameter in a deny_log manage acti...Show more |