Skip to main content

Vendor archive

keplerproject CVEs

Beta · best-effort

3 CVEs tagged to vendor keplerproject0 Critical, 0 High, 3 Medium, 0 Low, 0 Unrated.

CVE-2014-2875

Published Feb 6, 2020

The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attackers to hijack arbitrary sessions via a br…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10400

Published Feb 6, 2020

The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID and hijack arbitrary sessions. NOTE: this…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort

CVE-2014-10399

Published Feb 6, 2020

The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions. NOTE: this vulnerability was SPLIT from CVE-…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 1-3 of 3 CVEsPage 1 of 1