5.8
CVSSv2

CVE-2008-4325

Published: 30/09/2008 Updated: 30/08/2010
CVSS v2 Base Score: 5.8 | Impact Score: 4.9 | Exploitability Score: 8.6
VMScore: 516
Vector: AV:N/AC:M/Au:N/C:N/I:P/A:P

Vulnerability Summary

lib/viewvc.py in ViewVC 1.0.5 uses the content-type parameter in the HTTP request for the Content-Type header in the HTTP response, which allows remote malicious users to cause content to be misinterpreted by the browser via a content-type parameter that is inconsistent with the requested object. NOTE: this issue might not be a vulnerability, since it requires attacker access to the repository that is being viewed.

Vulnerable Product Search on Vulmon Subscribe to Product

viewvc viewvc 1.0.5

Vendor Advisories

Debian Bug report logs - #500779 CVE-2008-4325: misinterpretation of content-type Package: viewvc; Maintainer for viewvc is Lev Lamberov <dogsleg@debianorg>; Source for viewvc is src:viewvc (PTS, buildd, popcon) Reported by: Steffen Joeris <steffenjoeris@skolelinuxde> Date: Wed, 1 Oct 2008 11:39:02 UTC Severity: ...