Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-4325

Опубликовано: 30 сент. 2008
Источник: nvd
CVSS2: 5.8
EPSS Низкий

Описание

lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:viewvc:viewvc:1.0.5:*:*:*:*:*:*:*

EPSS

Процентиль: 71%
0.01447
Низкий

5.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

ubuntu
почти 18 лет назад

lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.

debian
почти 18 лет назад

lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the H ...

github
больше 4 лет назад

lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote attackers to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.

EPSS

Процентиль: 71%
0.01447
Низкий

5.8 Medium

CVSS2

Дефекты

NVD-CWE-noinfo