6.5

CVE-2007-3255

Multiple cross-site request forgery (CSRF) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to execute commands as arbitrary users via (1) a saved Workflow name or (2) the Content-Type HTTP header.  NOTE: item 2 also affects the same version numbers of Xythos Digital Locker (XDL). One or both vectors might also affect Xythos WebFile Server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
XythosEnterprise Document Manager Version <= 5.0.25.7
XythosEnterprise Document Manager Version <= 6.0.46.0
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.94% 0.775
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/25783
http://securityreason.com/securityalert/2845
http://securitytracker.com/id?1018291
http://securitytracker.com/id?1018292
http://www.securityfocus.com/archive/1/472275/100/0/threaded
http://www.securityfocus.com/bid/24521
Patch
http://www.symantec.com/content/en/us/enterprise/research/SYMSA-2007-004.txt
http://osvdb.org/37615
http://osvdb.org/37616
https://exchange.xforce.ibmcloud.com/vulnerabilities/35084