7.5

CVE-2007-0184

Getahead Direct Web Remoting (DWR) before 1.1.4 allows attackers to obtain unauthorized access to public methods via a crafted request that bypasses the include/exclude checks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
GetaheadDirect Web Remoting Version <= 1.1.3
GetaheadDirect Web Remoting Version0.7
GetaheadDirect Web Remoting Version0.8
GetaheadDirect Web Remoting Version0.9
GetaheadDirect Web Remoting Version1.0
GetaheadDirect Web Remoting Version1.1.0
GetaheadDirect Web Remoting Version1.1.1
GetaheadDirect Web Remoting Version1.1.2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.44% 0.697
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://lists.opensuse.org/opensuse-security-announce/2009-02/msg00002.html
http://getahead.ltd.uk/dwr/changelog
http://osvdb.org/32657
http://secunia.com/advisories/23641
Vendor Advisory
http://www.securityfocus.com/bid/21955
http://www.vupen.com/english/advisories/2007/0095
https://exchange.xforce.ibmcloud.com/vulnerabilities/31377