Apereo / Phpcas
9 CVEs
| CVE ID | Description | Severity | CVSS | Published |
|---|---|---|---|---|
| CVE-2022-39369 | Service Hostname Discovery Exploitation in phpCAS | HIGH | 8.0 | Nov 1, 2022 |
| CVE-2014-4172 | cas-client: Bypass of security constraints via URL parameter injection | CRITICAL | 9.8 | Jan 24, 2020 |
| CVE-2012-1105 | An Information Disclosure vulnerability exists in the Jasig Project php-pear-CAS 1.2.2 package in the /tmp directory. The Central Authentication Service client… | MEDIUM | 5.5 | Dec 5, 2019 |
| CVE-2012-1104 | A Security Bypass vulnerability exists in the phpCAS 1.2.2 library from the jasig project due to the way proxying of services are managed. | MEDIUM | 5.3 | Dec 5, 2019 |
| CVE-2017-1000071 | Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server. | HIGH | 8.1 | Jul 13, 2017 |
| CVE-2012-5583 | phpCAS before 1.3.2 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certi… | MEDIUM | 5.8 | Jun 6, 2014 |
| CVE-2010-3692 | Directory traversal vulnerability in the callback function in client.php in phpCAS before 1.1.3, when proxy mode is enabled, allows remote attackers to create… | MEDIUM | 6.4 | Oct 7, 2010 |
| CVE-2010-3691 | PGTStorage/pgt-file.php in phpCAS before 1.1.3, when proxy mode is enabled, allows local users to overwrite arbitrary files via a symlink attack on an unspecif… | LOW | 3.3 | Oct 7, 2010 |
| CVE-2010-3690 | Multiple cross-site scripting (XSS) vulnerabilities in phpCAS before 1.1.3, when proxy mode is enabled, allow remote attackers to inject arbitrary web script o… | MEDIUM | 4.3 | Oct 7, 2010 |
Showing 1 to 9 of 9 CVEs