Lucene search

K
nvd[email protected]NVD:CVE-2013-3514
HistoryMay 14, 2014 - 7:55 p.m.

CVE-2013-3514

2014-05-1419:55:09
CWE-22
web.nvd.nist.gov
7

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.004

Percentile

72.8%

Multiple directory traversal vulnerabilities in OpenX before 2.8.10 revision 82710 allow remote administrators to read arbitrary files via a … (dot dot) in the group parameter to (1) plugin-preferences.php or (2) plugin-settings.php in www/admin, a different vulnerability than CVE-2013-7376. NOTE: this can be leveraged using CSRF to allow remote unauthenticated attackers to read arbitrary files.

Affected configurations

Nvd
Node
openxopenxRange2.8.10
OR
openxopenxMatch2.4
OR
openxopenxMatch2.4.4
OR
openxopenxMatch2.4.5
OR
openxopenxMatch2.4.6
OR
openxopenxMatch2.4.7
OR
openxopenxMatch2.4.8
OR
openxopenxMatch2.4.9
OR
openxopenxMatch2.4.10
OR
openxopenxMatch2.4.11
OR
openxopenxMatch2.6.0
OR
openxopenxMatch2.6.1
OR
openxopenxMatch2.6.2
OR
openxopenxMatch2.6.3
OR
openxopenxMatch2.6.4
OR
openxopenxMatch2.6.5
OR
openxopenxMatch2.7.29
OR
openxopenxMatch2.8
OR
openxopenxMatch2.8.1
OR
openxopenxMatch2.8.2
OR
openxopenxMatch2.8.3
OR
openxopenxMatch2.8.4
OR
openxopenxMatch2.8.5
OR
openxopenxMatch2.8.6
OR
openxopenxMatch2.8.7
OR
openxopenxMatch2.8.8
OR
openxopenxMatch2.8.9
VendorProductVersionCPE
openxopenx*cpe:2.3:a:openx:openx:*:*:*:*:*:*:*:*
openxopenx2.4cpe:2.3:a:openx:openx:2.4:*:*:*:*:*:*:*
openxopenx2.4.4cpe:2.3:a:openx:openx:2.4.4:*:*:*:*:*:*:*
openxopenx2.4.5cpe:2.3:a:openx:openx:2.4.5:*:*:*:*:*:*:*
openxopenx2.4.6cpe:2.3:a:openx:openx:2.4.6:*:*:*:*:*:*:*
openxopenx2.4.7cpe:2.3:a:openx:openx:2.4.7:*:*:*:*:*:*:*
openxopenx2.4.8cpe:2.3:a:openx:openx:2.4.8:*:*:*:*:*:*:*
openxopenx2.4.9cpe:2.3:a:openx:openx:2.4.9:*:*:*:*:*:*:*
openxopenx2.4.10cpe:2.3:a:openx:openx:2.4.10:*:*:*:*:*:*:*
openxopenx2.4.11cpe:2.3:a:openx:openx:2.4.11:*:*:*:*:*:*:*
Rows per page:
1-10 of 271

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

AI Score

6.8

Confidence

Low

EPSS

0.004

Percentile

72.8%