5

CVE-2007-1341

include/auth/auth.php in Simple Invoices before 2007 03 05 does not use the login system to protect print preview pages for invoices, which might allow attackers to obtain sensitive information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Simple InvoicesSimple Invoices Version2006-12-11
Simple InvoicesSimple Invoices Version2007-01-25
Simple InvoicesSimple Invoices Version2007-02-02
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.25% 0.654
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://code.google.com/p/simpleinvoices/issues/detail?id=35
http://forum.tufat.com/showthread.php?p=116753#post116753
http://osvdb.org/33860
http://secunia.com/advisories/24402
Vendor Advisory
http://www.securityfocus.com/bid/22818
Patch
Vendor Advisory
https://sourceforge.net/project/shownotes.php?group_id=164303&release_id=491300