Lucene search

K
nvd[email protected]NVD:CVE-2004-2254
HistoryDec 31, 2004 - 5:00 a.m.

CVE-2004-2254

2004-12-3105:00:00
web.nvd.nist.gov
4

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.037

Percentile

91.8%

SurgeLDAP 1.0g (Build 12), and possibly other versions before 1.0h, allows remote attackers to bypass authentication for the administration interface via a direct request to admin.cgi with a modified utoken parameter.

Affected configurations

Nvd
Node
netwinsurgeldapMatch1.0a
OR
netwinsurgeldapMatch1.0b
OR
netwinsurgeldapMatch1.0d
OR
netwinsurgeldapMatch1.0e
OR
netwinsurgeldapMatch1.0f
OR
netwinsurgeldapMatch1.0g
VendorProductVersionCPE
netwinsurgeldap1.0acpe:2.3:a:netwin:surgeldap:1.0a:*:*:*:*:*:*:*
netwinsurgeldap1.0bcpe:2.3:a:netwin:surgeldap:1.0b:*:*:*:*:*:*:*
netwinsurgeldap1.0dcpe:2.3:a:netwin:surgeldap:1.0d:*:*:*:*:*:*:*
netwinsurgeldap1.0ecpe:2.3:a:netwin:surgeldap:1.0e:*:*:*:*:*:*:*
netwinsurgeldap1.0fcpe:2.3:a:netwin:surgeldap:1.0f:*:*:*:*:*:*:*
netwinsurgeldap1.0gcpe:2.3:a:netwin:surgeldap:1.0g:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7

Confidence

Low

EPSS

0.037

Percentile

91.8%

Related for NVD:CVE-2004-2254