This page lists publicly disclosed CVE vulnerabilities affecting stanford webauth (linked via NVD CPE). Each row includes severity scores, summaries, and publication dates to help identify and analyze security issues.
| CVE | Summary | Source | Max CVSS | EPSS % | Published | Updated |
|---|---|---|---|---|---|---|
| CVE-2013-2106 | webauth before 4.6.1 has authentication credential disclosure | [email protected] | 7.5 | 1.58% | 2019-12-03 | 2024-11-21 |
| CVE-2009-2945 | weblogin/login.fcgi (aka the WebLogin login script) in Stanford University WebAuth 3.5.5, 3.6.0, and 3.6.1 places passwords in URLs in certain circumstances involving conversion of a POST request to a GET request, which allows context-dependent attackers to discover passwords by reading (1) web-server access logs, (2) web-server Referer logs, or (3) the browser history. | [email protected] | 4.3 | 0.86% | 2009-09-15 | 2026-04-23 |