Логотип exploitDog
bind:CVE-2007-4888
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2007-4888

Количество 2

Количество 2

nvd логотип

CVE-2007-4888

больше 18 лет назад

The "You are not allowed..." error handler in XWiki 1.0 B1 and 1.0 B2 associates the doc variable with the entire document content and metadata regardless of a user's view rights, which allows remote authenticated users to read arbitrary documents via a custom skin that prints the content attribute of the doc variable.

CVSS2: 3.5
EPSS: Низкий
github логотип

GHSA-fx4h-wx28-j62f

почти 4 года назад

The "You are not allowed..." error handler in XWiki 1.0 B1 and 1.0 B2 associates the doc variable with the entire document content and metadata regardless of a user's view rights, which allows remote authenticated users to read arbitrary documents via a custom skin that prints the content attribute of the doc variable.

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2007-4888

The "You are not allowed..." error handler in XWiki 1.0 B1 and 1.0 B2 associates the doc variable with the entire document content and metadata regardless of a user's view rights, which allows remote authenticated users to read arbitrary documents via a custom skin that prints the content attribute of the doc variable.

CVSS2: 3.5
0%
Низкий
больше 18 лет назад
github логотип
GHSA-fx4h-wx28-j62f

The "You are not allowed..." error handler in XWiki 1.0 B1 and 1.0 B2 associates the doc variable with the entire document content and metadata regardless of a user's view rights, which allows remote authenticated users to read arbitrary documents via a custom skin that prints the content attribute of the doc variable.

0%
Низкий
почти 4 года назад

Уязвимостей на страницу