Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-5184

Опубликовано: 21 нояб. 2008
Источник: ubuntu
Приоритет: low
EPSS Низкий
CVSS2: 10

Описание

The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.

РелизСтатусПримечание
dapper

DNE

devel

not-affected

1.3.9-11
gutsy

DNE

hardy

DNE

intrepid

not-affected

1.3.9-2ubuntu6
upstream

needs-triage

Показывать по

РелизСтатусПримечание
dapper

not-affected

1.2.2-0ubuntu0.6.06.11
devel

DNE

gutsy

released

1.3.2-1ubuntu7.9
hardy

released

1.3.7-1ubuntu3.3
intrepid

DNE

upstream

needs-triage

Показывать по

EPSS

Процентиль: 49%
0.00285
Низкий

10 Critical

CVSS2

Связанные уязвимости

redhat
больше 17 лет назад

The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.

nvd
почти 17 лет назад

The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.

debian
почти 17 лет назад

The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the gues ...

github
больше 3 лет назад

The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.

EPSS

Процентиль: 49%
0.00285
Низкий

10 Critical

CVSS2