Lucene search

K
jvnJapan Vulnerability NotesJVN:03975805
HistoryMay 16, 2016 - 12:00 a.m.

JVN#03975805: a-blog cms vulnerable to session management

2016-05-1600:00:00
Japan Vulnerability Notes
jvn.jp
20

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS

0.002

Percentile

58.5%

a-blog cms provided by appleple Inc. is a content management system (CMS). a-blog cms contains a vulnerability in session management of the comment functionality.

Impact

An arbitrary comment posted may be deleted or a commenter’s e-mail address may be obtained by an unauthenticated remote attacker.

Solution

Apply the Patch
Apply the patch according to the information provided by the developer.
If a user has customized a-blog cms, modifying some of the templates may be necessary.
For details, refer to the readme.md contained in the patch.

Products Affected

  • a-blog cms 2.6.0.1 and earlier

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:P/A:N

CVSS3

6.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

LOW

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

EPSS

0.002

Percentile

58.5%

Related for JVN:03975805