4
CVSSv2

CVE-2013-6404

Published: 09/12/2013 Updated: 29/08/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 356
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Quassel core (server daemon) in Quassel IRC prior to 0.9.2 does not properly verify the user ID when accessing user backlogs, which allows remote authenticated users to read other users' backlogs via the bufferid in (1) 16/select_buffer_by_id.sql, (2) 16/select_buffer_by_id.sql, and (3) 16/select_buffer_by_id.sql in core/SQL/PostgreSQL/.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

quassel-irc quassel irc

quassel-irc quassel irc 0.9.0