Vulnerabilities
Vulnerable Software
Simplesamlphp:  >> Simplesamlphp  Security Vulnerabilities
The SimpleSAML_XML_Validator class constructor in SimpleSAMLphp before 1.14.11 might allow remote attackers to spoof signatures on SAML 1 responses or possibly cause a denial of service (memory consumption) by leveraging improper conversion of return values to boolean.
CVSS Score
6.3
EPSS Score
0.012
Published
2017-02-17
The sanitycheck module in SimpleSAMLphp before 1.14.1 allows remote attackers to learn the PHP version on the system via unspecified vectors.
CVSS Score
5.3
EPSS Score
0.013
Published
2017-02-07
Cross-site scripting (XSS) vulnerability in modules/core/www/no_cookie.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the retryURL parameter.
CVSS Score
4.3
EPSS Score
0.014
Published
2012-01-24
Cross-site scripting (XSS) vulnerability in logout.php in SimpleSAMLphp 1.8.1 and possibly other versions before 1.8.2 allows remote attackers to inject arbitrary web script or HTML via the link_href parameter.
CVSS Score
4.3
EPSS Score
0.013
Published
2012-01-24


Contact Us

Shodan ® - All rights reserved