6.5
CVE-2007-2233
- EPSS 1.99%
- Veröffentlicht 25.04.2007 15:19:00
- Zuletzt bearbeitet 16.06.2026 22:39:11
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.99% | 0.781 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
http://secunia.com/advisories/24845
http://www.securityfocus.com/archive/1/465386/100/100/threaded
http://www.vupen.com/english/advisories/2007/1359
http://www.umich.edu/~umweb/software/cosign/cosign-vuln-2007-002.txt