Lucene search

K
cveMitreCVE-2008-0210
HistoryJan 10, 2008 - 12:46 a.m.

CVE-2008-0210

2008-01-1000:46:00
CWE-287
mitre
web.nvd.nist.gov
22
cve-2008-0210
uebimiau webmail
authentication bypass
directory traversal
http security

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.8

Confidence

Low

EPSS

0.005

Percentile

77.0%

Uebimiau Webmail 2.7.10 and 2.7.2 does not protect authentication state variables from being set through HTTP requests, which allows remote attackers to bypass authentication via a sess[auth]=1 parameter settting. NOTE: this can be leveraged to conduct directory traversal attacks without authentication by using CVE-2008-0140.

Affected configurations

Nvd
Node
uebimiauwebmailMatch2.7.2
OR
uebimiauwebmailMatch2.7.10
VendorProductVersionCPE
uebimiauwebmail2.7.2cpe:2.3:a:uebimiau:webmail:2.7.2:*:*:*:*:*:*:*
uebimiauwebmail2.7.10cpe:2.3:a:uebimiau:webmail:2.7.10:*:*:*:*:*:*:*

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

AI Score

6.8

Confidence

Low

EPSS

0.005

Percentile

77.0%

Related for CVE-2008-0210