Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-4325

Опубликовано: 30 сент. 2008
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:viewvc:viewvc:1.0.5:*:*:*:*:*:*:*

EPSS

Процентиль: 75%
0.00897
Низкий

5.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

ubuntu
больше 17 лет назад

lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.

debian
больше 17 лет назад

lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the H ...

github
почти 4 года назад

lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.

EPSS

Процентиль: 75%
0.00897
Низкий

5.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo