Lucene search

K
freebsdFreeBSD209F0D75-4B5C-11DC-A6CD-000FB5066B20
HistoryMar 13, 2007 - 12:00 a.m.

flyspray -- authentication bypass

2007-03-1300:00:00
vuxml.freebsd.org
17

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.013 Low

EPSS

Percentile

85.6%

The Flyspray Project reports:

Flyspray authentication system can be bypassed by sending a
carefully crafted post request.
To be vulnerable, PHP configuration directive output_buffering
has to be disabled or set to a low value.

OSVersionArchitecturePackageVersionFilename
FreeBSDanynoarchflyspray< 0.9.9.2UNKNOWN

6.8 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:M/Au:N/C:P/I:P/A:P

0.013 Low

EPSS

Percentile

85.6%

Related for 209F0D75-4B5C-11DC-A6CD-000FB5066B20