Описание
Harmoni before 1.6.0 does not require administrative privileges to list (1) user names or (2) asset ids, which allows remote attackers to obtain sensitive information.
Harmoni before 1.6.0 does not require administrative privileges to list (1) user names or (2) asset ids, which allows remote attackers to obtain sensitive information.
Ссылки
- https://nvd.nist.gov/vuln/detail/CVE-2008-3717
- https://exchange.xforce.ibmcloud.com/vulnerabilities/44485
- http://secunia.com/advisories/31503
- http://sourceforge.net/project/shownotes.php?release_id=619864
- http://sourceforge.net/tracker/index.php?func=detail&aid=2040324&group_id=82171&atid=1098812
- http://www.securityfocus.com/bid/30706
EPSS
Процентиль: 57%
0.00357
Низкий
CVE ID
Связанные уязвимости
nvd
больше 17 лет назад
Harmoni before 1.6.0 does not require administrative privileges to list (1) user names or (2) asset ids, which allows remote attackers to obtain sensitive information.
EPSS
Процентиль: 57%
0.00357
Низкий