5
CVE-2008-0407
- EPSS 1.57%
- Veröffentlicht 29.01.2008 00:00:00
- Zuletzt bearbeitet 16.06.2026 22:49:33
- Quelle cve@mitre.org
- CVE-Watchlists
- Unerledigt
HTTP File Server (HFS) before 2.2c tags HTTP request log entries with the username sent during HTTP Basic Authentication, regardless of whether authentication succeeded, which might make it more difficult for an administrator to determine who made a remote request.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Hfs ≫ Http File Server Version <= 2.2b
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.57% | 0.721 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
CWE-287 Improper Authentication
When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
http://secunia.com/advisories/28631
http://www.rejetto.com/hfs/?f=wn
http://www.securityfocus.com/bid/27423
http://www.syhunt.com/advisories/hfshack.txt
http://securityreason.com/securityalert/3582
http://www.securityfocus.com/archive/1/486874/100/0/threaded
http://www.syhunt.com/advisories/hfs-1-username.txt
https://exchange.xforce.ibmcloud.com/vulnerabilities/39877