Vulnerability Name: | CCN-10312 | ||||||
Published: | 2002-10-07 | ||||||
Updated: | 2002-10-07 | ||||||
Summary: | Zope could allow a remote attacker to obtain sensitive information. If a remote attacker accesses the Web management interface and attempts to login with invalid credentials, then clicks "Cancel" after the failed login attempt, an error message would be returned that contains sensitive information, including full path information. An attacker could then use this information to launch further attacks against the affected system. | ||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||
CVSS v2 Severity: | 5.0 Medium (CCN CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||
Vulnerability Consequences: | Obtain Information | ||||||
References: | Source: CCN Type: BugTraq Mailing List, Mon Oct 07 2002 - 03:26:37 CDT Re: Insecure XML-RPC handling in Zope reveals the distribution physic al location. Source: CCN Type: BID-5903 Zope Failed Login Information Disclosure Vulnerability Source: CCN Type: Zope Web site Welcome to Zope.org Source: XF Type: UNKNOWN zope-login-information-disclosure(10312) | ||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||
BACK |