Логотип exploitDog
bind:CVE-2010-4408
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2010-4408

Количество 2

Количество 2

nvd логотип

CVE-2010-4408

около 15 лет назад

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.

CVSS2: 6.8
EPSS: Низкий
github логотип

GHSA-5p54-jj38-3hxj

больше 3 лет назад

Apache Archiva does not require entry of the administrator's password at the time of modifying a user account

EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2010-4408

Apache Archiva 1.0 through 1.0.3, 1.1 through 1.1.4, 1.2 through 1.2.2, and 1.3 through 1.3.1 does not require entry of the administrator's password at the time of modifying a user account, which makes it easier for context-dependent attackers to gain privileges by leveraging a (1) unattended workstation or (2) cross-site request forgery (CSRF) vulnerability, a related issue to CVE-2010-3449.

CVSS2: 6.8
1%
Низкий
около 15 лет назад
github логотип
GHSA-5p54-jj38-3hxj

Apache Archiva does not require entry of the administrator's password at the time of modifying a user account

1%
Низкий
больше 3 лет назад

Уязвимостей на страницу