Lucene search

K
cve[email protected]CVE-2007-1830
HistoryApr 03, 2007 - 12:19 a.m.

CVE-2007-1830

2007-04-0300:19:00
web.nvd.nist.gov
19
vulnerability
username hijacking
web-app.org
webapp
administrative access
remote attack
xss
cookies exploit

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

64.5%

Unspecified vulnerability in the Username Hijacking Patch 20070312 for web-app.org WebAPP 0.9.9.6 allows remote attackers to obtain administrative access via unknown vectors, related to “something overlooked in the original that was still overlooked in the patch”, and possibly related to copying files to the user-lib and the “XSS and cookies exploit.”

Affected configurations

NVD
Node
web-app.orgwebappMatch0.9.9.6

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:N/I:P/A:N

6.8 Medium

AI Score

Confidence

Low

0.002 Low

EPSS

Percentile

64.5%

Related for CVE-2007-1830