3.5
CVE-2007-2746
- EPSS 0.92%
- Veröffentlicht 17.05.2007 20:30:00
- Zuletzt bearbeitet 16.06.2026 22:40:14
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
The viewList function in lib/WebGUI/Asset/Wobject/DataForm.pm in Plain Black WebGUI before 7.3.14 does not properly use data structures containing privilege information, which allows remote authenticated users to obtain sensitive information or possibly have other unspecified impact.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Plain Black ≫ Webgui Version <= 7.3.14
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.92% | 0.557 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 3.5 | 6.8 | 2.9 |
AV:N/AC:M/Au:S/C:P/I:N/A:N
|
http://osvdb.org/36566
http://secunia.com/advisories/25355
http://www.plainblack.com/bugs/tracker/dataform-security-bug
http://www.vupen.com/english/advisories/2007/1840