[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248038

 
 

909

 
 

194772

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-0240Date: (C)2009-01-20   (M)2023-12-22


listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 3.5
Exploit Score: 6.8
Impact Score: 2.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: MEDIUM
Authentication: SINGLE
Confidentiality: PARTIAL
Integrity: NONE
Availability: NONE
  
Reference:
SECUNIA-32338
SECUNIA-33945
SECUNIA-34191
DSA-1725
GLSA-200903-20
http://www.openwall.com/lists/oss-security/2009/01/18/2
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512191
websvn-listing-information-disclosure(48171)

CWE    1
CWE-264
OVAL    2
oval:org.mitre.oval:def:8233
oval:org.secpod.oval:def:600518

© SecPod Technologies