Lucene search

K
nvd[email protected]NVD:CVE-2010-1191
HistoryMar 31, 2010 - 6:00 p.m.

CVE-2010-1191

2010-03-3118:00:00
CWE-287
web.nvd.nist.gov
1

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.008

Percentile

82.1%

Sahana disaster management system 0.6.2.2, and possibly other versions, allows remote attackers to bypass intended access restrictions and disable administrator authentication via a direct request to stream.php in an acl_enable_acl action to the admin module.

Affected configurations

NVD
Node
sahanafoundationsahanaMatch0.6.2.2

CVSS2

6.4

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

NONE

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:N/I:P/A:P

AI Score

6.8

Confidence

Low

EPSS

0.008

Percentile

82.1%

Related for NVD:CVE-2010-1191