Vdgsecurity

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 7
    Known Exploited: 0
    0
    Critical Level Threats
    1
    High Level Threats
    6
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2014-9575

    VDG Security SENSE (formerly DIVA) before 2.3.15 allows remote attackers to bypass authentication, and consequently read and modify arbitrary plugin settings, via an encoded : (colon) character in the Authorization HTTP header.

    Last Modified: Apr 12, 2025
    Published: Jan 08, 2015

    CVE-2014-9578

    VDG Security SENSE (formerly DIVA) 2.3.13 performs authentication with a password hash instead of a password, which allows remote attackers to gain login access by leveraging knowledge of a password hash.

    Last Modified: Apr 12, 2025
    Published: Jan 08, 2015

    CVE-2014-9579

    VDG Security SENSE (formerly DIVA) 2.3.13 stores administrator credentials in cleartext, which allows attackers to obtain sensitive information by reading the plugin configuration files.

    Last Modified: Apr 12, 2025
    Published: Jan 08, 2015

    CVE-2014-9577

    VDG Security SENSE (formerly DIVA) 2.3.13 sends the user database when a user logs in, which allows remote authenticated users to obtain usernames and password hashes by logging in to TCP port 51410 and reading the response.

    Last Modified: Apr 12, 2025
    Published: Jan 08, 2015

    CVE-2014-9576

    VDG Security SENSE (formerly DIVA) 2.3.13 has a hardcoded password of (1) ArpaRomaWi for the root Postgres account and !DVService for the (2) postgres and (3) NTP Windows user accounts, which allows remote attackers to obtain access.

    Last Modified: Apr 12, 2025
    Published: Jan 08, 2015
    Items Per Page
    Vdgsecurity Vulnerabilities & Security CVEs | CVE-DB