CVE-2015-6538
27.12.2015, 19:59
The login page in Epiphany Cardio Server 3.3, 4.0, and 4.1 mishandles authentication requests, which allows remote attackers to conduct LDAP injection attacks, and consequently bypass intended access restrictions, via a crafted URL.Enginsight
| Vendor | Product | Version |
|---|---|---|
| ephiphanyheathdata | cardio_server | 3.3 |
| ephiphanyheathdata | cardio_server | 4.0 |
| ephiphanyheathdata | cardio_server | 4.1 |
𝑥
= Vulnerable software versions