Vulnerability Name: | CVE-2005-2600 (CCN-21803) | ||||||||||||
Assigned: | 2005-08-12 | ||||||||||||
Published: | 2005-08-12 | ||||||||||||
Updated: | 2008-09-05 | ||||||||||||
Summary: | FUDForum 2.6.15 with "Tree View" enabled, as used in other products such as phpgroupware and egroupware, allows remote attackers to read private posts via a modified mid parameter. | ||||||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-Other | ||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||
References: | Source: FULLDISC Type: Patch 20050811 Fudforum: incompletely check of user rights in tree view gaining access to all messages Source: MITRE Type: CNA CVE-2005-2600 Source: CCN Type: FUDforum Web site FUD Forum Source: CCN Type: SA16414 FUDforum "Tree View" Security Bypass Vulnerability Source: SECUNIA Type: Patch, Vendor Advisory 16414 Source: SECUNIA Type: UNKNOWN 17643 Source: DEBIAN Type: UNKNOWN DSA-798 Source: DEBIAN Type: UNKNOWN DSA-899 Source: DEBIAN Type: DSA-798 phpgroupware -- several vulnerabilities Source: DEBIAN Type: DSA-899 egroupware -- programming errors Source: CCN Type: GLSA-200508-20 phpGroupWare: Multiple vulnerabilities Source: CCN Type: OSVDB ID: 18699 FUDforum mid Variable Tree View Arbitrary Restricted Message Access Source: CCN Type: phpGroupWare Web site phpGroupWare.org Source: BID Type: UNKNOWN 14556 Source: CCN Type: BID-14556 FUDForum Tree View Access Validation Vulnerability Source: XF Type: UNKNOWN fudforum-tree-view-bypass-security(21803) | ||||||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||||||
Oval Definitions | |||||||||||||
| |||||||||||||
BACK |