5

CVE-2008-6470

Multiple unspecified vulnerabilities in ClanSphere before 2008.2.1 allow remote attackers to obtain sensitive information, and possibly have unknown other impact, via vectors related to "javascript insert" and the (1) mods/messages/getusers.php and (2) mods/abcode/listimg.php files.  NOTE: some of these details are obtained from third party information.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
ClansphereClansphere Version <= 2008
ClansphereClansphere Version2007.3.1
ClansphereClansphere Version2007.4
ClansphereClansphere Version2007.4.1
ClansphereClansphere Version2007.4.2
ClansphereClansphere Version2007.4.3
ClansphereClansphere Version2007.4.4
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.49% 0.707
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://osvdb.org/48451
http://secunia.com/advisories/31965
Vendor Advisory
http://sourceforge.net/project/shownotes.php?release_id=627530
Patch
http://www.clansphere.net/index/news/view/id/289
Vendor Advisory
http://www.clansphere.net/index/news/view/id/306
Vendor Advisory
http://www.securityfocus.com/bid/31293
https://exchange.xforce.ibmcloud.com/vulnerabilities/45269