Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-ffrg-vhg2-pcm5

Опубликовано: 01 мая 2022
Источник: github
Github: Не прошло ревью

Описание

ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be reached by traversing a forbidden object, or (3) forbidden diff view path parameters.

ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be reached by traversing a forbidden object, or (3) forbidden diff view path parameters.

EPSS

Процентиль: 72%
0.00718
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
больше 17 лет назад

ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be reached by traversing a forbidden object, or (3) forbidden diff view path parameters.

nvd
больше 17 лет назад

ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be reached by traversing a forbidden object, or (3) forbidden diff view path parameters.

debian
больше 17 лет назад

ViewVC before 1.0.5 provides revision metadata without properly checki ...

EPSS

Процентиль: 72%
0.00718
Низкий

Дефекты

CWE-200