Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-3255

Опубликовано: 27 июн. 2007
Источник: nvd
CVSS2: 6.5
EPSS Низкий

Описание

Multiple cross-site request forgery (CSRF) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to execute commands as arbitrary users via (1) a saved Workflow name or (2) the Content-Type HTTP header. NOTE: item 2 also affects the same version numbers of Xythos Digital Locker (XDL). One or both vectors might also affect Xythos WebFile Server.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:xythos:enterprise_document_manager:*:*:*:*:*:*:*:*
Версия до 5.0.25.7 (включая)
cpe:2.3:a:xythos:enterprise_document_manager:*:*:*:*:*:*:*:*
Версия до 6.0.46.0 (включая)

EPSS

Процентиль: 78%
0.01192
Низкий

6.5 Medium

CVSS2

Дефекты

NVD-CWE-Other

Связанные уязвимости

github
почти 4 года назад

Multiple cross-site request forgery (CSRF) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to execute commands as arbitrary users via (1) a saved Workflow name or (2) the Content-Type HTTP header. NOTE: item 2 also affects the same version numbers of Xythos Digital Locker (XDL). One or both vectors might also affect Xythos WebFile Server.

EPSS

Процентиль: 78%
0.01192
Низкий

6.5 Medium

CVSS2

Дефекты

NVD-CWE-Other