Skip to content
Noroxi

keplerproject records

3 published records for vendor keplerproject.

Researcher profile

Entered KEV
0 · 0%
Weaponized
0 · 0%
Pre-auth RCE
0
With a fix record
0%
Median publish → KEV
No record has entered KEV

Records by year

  1. 20

Bar: total · dark part: CISA KEV.

Recurring classes

The weakness classes this vendor ships most often: where to look.

CWE

Attack profile

All records

3 records
  • CVE-2014-2875
    24Monitor

    The session.lua library in CGILua 5.2 alpha 1 and 5.2 alpha 2 uses weak session IDs generated based on OS time, which allows remote attacker

    MediumCVSS 6.1No exploitEPSS 2%

    keplerproject · cgiluaFeb 6, 2020

  • The session.lua library in CGILua 5.1.x uses the same ID for each session, which allows remote attackers to hijack arbitrary sessions.

    MediumCVSS 6.1No exploitEPSS 1%

    keplerproject · cgiluaFeb 6, 2020

  • The session.lua library in CGILua 5.0.x uses sequential session IDs, which makes it easier for remote attackers to predict the session ID an

    MediumCVSS 6.1No exploitEPSS 1%

    keplerproject · cgiluaFeb 6, 2020