Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2013-1290

Опубликовано: 09 апр. 2013
Источник: nvd
CVSS2: 3.5
EPSS Средний

Описание

Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via a direct request for a list's location, aka "Incorrect Access Rights Information Disclosure Vulnerability."

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:microsoft:sharepoint_server:2013:*:*:*:*:*:*:*

EPSS

Процентиль: 94%
0.13302
Средний

3.5 Low

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
больше 3 лет назад

Microsoft SharePoint Server 2013, in certain configurations involving legacy My Sites, does not properly establish default access controls for a SharePoint list, which allows remote authenticated users to bypass intended restrictions on reading list items via a direct request for a list's location, aka "Incorrect Access Rights Information Disclosure Vulnerability."

EPSS

Процентиль: 94%
0.13302
Средний

3.5 Low

CVSS2

Дефекты

CWE-264