Vulmon
Recent Vulnerabilities
Research Posts
Trends
Blog
About
Contact
Vulmon Alerts
By Relevance
By Risk Score
By Publish Date
ipsilon-project ipsilon vulnerabilities and exploits
(subscribe to this query)
383
VMScore
CVE-2015-5215
The default configuration of the Jinja templating engine used in the Identity Provider (IdP) server in Ipsilon 0.1.0 prior to 1.0.1 does not enable auto-escaping, which makes it easier for remote malicious users to conduct cross-site scripting (XSS) attacks via template variables...
Ipsilon-project Ipsilon
383
VMScore
CVE-2015-5216
The Identity Provider (IdP) server in Ipsilon 0.1.0 prior to 1.0.1 does not properly escape certain characters in a Python exception-message template, which makes it easier for remote malicious users to conduct cross-site scripting (XSS) attacks via an HTTP response.
Ipsilon-project Ipsilon
356
VMScore
CVE-2015-5217
providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 prior to 1.0.1 does not properly check permissions to update the SAML2 Service Provider (SP) owner, which allows remote authenticated users to cause a denial of service via a duplicate SP name.
Ipsilon Project Ipsilon 0.3.0
Ipsilon Project Ipsilon 0.1.0
Ipsilon Project Ipsilon 0.4.0
Ipsilon Project Ipsilon 0.5.0
Ipsilon Project Ipsilon 0.6.0
Ipsilon Project Ipsilon 1.0.0
490
VMScore
CVE-2015-5301
providers/saml2/admin.py in the Identity Provider (IdP) server in Ipsilon 0.1.0 prior to 1.0.2 and 1.1.x prior to 1.1.1 does not properly check permissions, which allows remote authenticated users to cause a denial of service by deleting a SAML2 Service Provider (SP).
Ipsilon Project Ipsilon 0.4.0
Ipsilon Project Ipsilon 0.5.0
Ipsilon Project Ipsilon 0.6.0
Ipsilon Project Ipsilon 1.1.0
Ipsilon Project Ipsilon 1.0.0
Ipsilon Project Ipsilon 1.0.1
Ipsilon Project Ipsilon 0.1.0
Ipsilon Project Ipsilon 0.3.0
VMScore
CVSSv2
CVSSv3
VMScore
Recommendations:
camera
bypass
CVE-2024-3592
CVE-2024-37383
CVE-2024-24919
CVE-2024-27822
CVE-2024-36788
CVE-2024-36789
man-in-the-middle
Vulnerability Notification Service
You don’t have to wait for vulnerability scanning results
Get Started