[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2009-2737Date: (C)2009-08-11   (M)2023-12-22


The EditCSVAction function in cgi/actions.py in Roundup 1.2 before 1.2.1, 1.4 through 1.4.6, and possibly other versions does not properly check permissions, which allows remote authenticated users with edit or create privileges for a class to modify arbitrary items within that class, as demonstrated by editing all queries, modifying settings, and adding roles to users.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 5.5
Exploit Score: 8.0
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: SINGLE
Confidentiality: NONE
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-34059
SECUNIA-34192
OSVDB-56368
DSA-1754
FEDORA-2009-2583
FEDORA-2009-2591
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=518768
http://issues.roundup-tracker.org/issue2550521
https://bugzilla.redhat.com/show_bug.cgi?id=489355

CWE    1
CWE-264
OVAL    2
oval:org.mitre.oval:def:7366
oval:org.secpod.oval:def:600428

© SecPod Technologies