Vulnerabilities (CVE)

Filtered by vendor Pulsesecure Subscribe
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-11195 1 Pulsesecure 1 Pulse Connect Secure 2017-07-19 4.3 MEDIUM 6.1 MEDIUM
Pulse Connect Secure 8.3R1 has Reflected XSS in launchHelp.cgi. The helpLaunchPage parameter is reflected in an IFRAME element, if the value contains two quotes. It properly sanitizes quotes and tags, so one cannot simply close the src with a quote and inject after that. However, an attacker can use javascript: or data: to abuse this.
CVE-2017-11194 1 Pulsesecure 1 Pulse Connect Secure 2017-07-17 4.3 MEDIUM 6.1 MEDIUM
Pulse Connect Secure 8.3R1 has Reflected XSS in adminservercacertdetails.cgi. In the admin panel, the certid parameter of adminservercacertdetails.cgi is reflected in the application's response and is not properly sanitized, allowing an attacker to inject tags. An attacker could come up with clever payloads to make the system run commands such as ping, ping6, traceroute, nslookup, arp, etc.
CVE-2016-4792 1 Pulsesecure 1 Pulse Connect Secure 2016-05-26 5.0 MEDIUM 5.3 MEDIUM
Pulse Connect Secure (PCS) 8.2 before 8.2r1 allows remote attackers to disclose sign in pages via unspecified vectors.
CVE-2016-3985 1 Pulsesecure 1 Pulse Connect Secure 2016-04-18 3.3 LOW 6.5 MEDIUM
The Terminal Services Remote Desktop Protocol (RDP) client session restrictions feature in Pulse Connect Secure (aka PCS) 8.1R7 and 8.2R1 allow remote authenticated users to bypass intended access restrictions via unspecified vectors.