7.5
CVSSv2

CVE-2010-0005

Published: 29/01/2010 Updated: 02/02/2010
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 668
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

query.py in the query interface in ViewVC prior to 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote malicious users to bypass intended access restrictions via a query.

Vulnerable Product Search on Vulmon Subscribe to Product

viewvc viewvc 1.0.6

viewvc viewvc 1.1.1

viewvc viewvc

viewvc viewvc 1.0.5

viewvc viewvc 1.1.0

viewvc viewvc 1.0.7

viewvc viewvc 1.0.8

viewvc viewvc 1.0.4

viewvc viewvc 1.0.3

viewvc viewvc 1.0.1

viewvc viewvc 1.0.2

Vendor Advisories

Debian Bug report logs - #575777 CVE-2010-0004 CVE-2010-0005 Package: viewvc; Maintainer for viewvc is Lev Lamberov <dogsleg@debianorg>; Source for viewvc is src:viewvc (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Mon, 29 Mar 2010 07:54:02 UTC Severity: serious Tags: security Fi ...
Debian Bug report logs - #576307 CVE-2010-0132: XSS via user-provided 'search_re' input Package: viewvc; Maintainer for viewvc is Lev Lamberov <dogsleg@debianorg>; Source for viewvc is src:viewvc (PTS, buildd, popcon) Reported by: Moritz Muehlenhoff <jmm@debianorg> Date: Fri, 2 Apr 2010 20:51:02 UTC Severity: gra ...
Debian Bug report logs - #575787 CVE-2010-0736: Cross-site scripting (XSS) vulnerability Package: viewvc; Maintainer for viewvc is Lev Lamberov <dogsleg@debianorg>; Source for viewvc is src:viewvc (PTS, buildd, popcon) Reported by: Giuseppe Iuculano <iuculano@debianorg> Date: Mon, 29 Mar 2010 09:12:02 UTC Severity ...