Vulnerability   
Search   
    Search 324607 CVE descriptions
and 145615 test descriptions,
access 10,000+ cross references.
Tests   CVE   All  

CVE ID:CVE-2017-5607
Description:Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 assigns the $C JS property to the global Window namespace, which might allow remote attackers to obtain sensitive logged-in username and version-related information via a crafted webpage.
Test IDs: 1.3.6.1.4.1.25623.1.0.106715   1.3.6.1.4.1.25623.1.0.106714  
Cross References: Common Vulnerability Exposure (CVE) ID: CVE-2017-5607
BugTraq ID: 97265
http://www.securityfocus.com/bid/97265
BugTraq ID: 97286
http://www.securityfocus.com/bid/97286
Bugtraq: 20170401 Splunk Enterprise Information Theft CVE-2017-5607 (Google Search)
http://www.securityfocus.com/archive/1/540346/100/0/threaded
https://www.exploit-db.com/exploits/41779/
http://seclists.org/fulldisclosure/2017/Mar/89
http://hyp3rlinx.altervista.org/advisories/SPLUNK-ENTERPRISE-INFORMATION-THEFT.txt
http://www.securitytracker.com/id/1038170




© 1998-2025 E-Soft Inc. All rights reserved.