Lucene search

K
cve[email protected]CVE-2013-7383
HistoryMay 20, 2014 - 2:55 p.m.

CVE-2013-7383

2014-05-2014:55:04
CWE-264
web.nvd.nist.gov
23
cve-2013-7383
x2gocleansessions
x2go server
remote authenticated users
gain privileges
unspecified vectors
backticks
nvd

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

6.7 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.9%

x2gocleansessions in X2Go Server before 4.0.0.8 and 4.0.1.x before 4.0.1.10 allows remote authenticated users to gain privileges via unspecified vectors, possibly related to backticks.

Affected configurations

NVD
Node
x2gox2go_serverRange4.0.0.7
OR
x2gox2go_serverMatch4.0.0.0
OR
x2gox2go_serverMatch4.0.0.1
OR
x2gox2go_serverMatch4.0.0.2
OR
x2gox2go_serverMatch4.0.0.3
OR
x2gox2go_serverMatch4.0.0.4
OR
x2gox2go_serverMatch4.0.0.6
OR
x2gox2go_serverMatch4.0.1.0
OR
x2gox2go_serverMatch4.0.1.1
OR
x2gox2go_serverMatch4.0.1.2
OR
x2gox2go_serverMatch4.0.1.3
OR
x2gox2go_serverMatch4.0.1.4
OR
x2gox2go_serverMatch4.0.1.5
OR
x2gox2go_serverMatch4.0.1.6
OR
x2gox2go_serverMatch4.0.1.7
OR
x2gox2go_serverMatch4.0.1.8
OR
x2gox2go_serverMatch4.0.1.9

9 High

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

6.7 Medium

AI Score

Confidence

Low

0.003 Low

EPSS

Percentile

70.9%