Vulnerabilities (CVE)

Filtered by vendor Skyboxsecurity Subscribe
Filtered by product Skybox Manager Client Application
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-14770 1 Skyboxsecurity 1 Skybox Manager Client Application 2017-10-11 2.1 LOW 5.5 MEDIUM
Skybox Manager Client Application prior to 8.5.501 is prone to an information disclosure vulnerability of user password hashes. A local authenticated attacker can access the password hashes in a debugger-pause state during the authentication process.
CVE-2017-14771 1 Skyboxsecurity 1 Skybox Manager Client Application 2017-10-11 3.6 LOW 5.5 MEDIUM
Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-supplied files path when uploading files via the application. During a debugger-pause state, a local authenticated attacker can upload an arbitrary file and overwrite existing files within the scope of the affected application.