3.5

CVE-2012-4954

The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a "parameter manipulation" issue.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
VanillaforumsVanilla Version <= 2.0.18.4
VanillaforumsVanilla Version2.0.0
VanillaforumsVanilla Version2.0.1
VanillaforumsVanilla Version2.0.2
VanillaforumsVanilla Version2.0.3
VanillaforumsVanilla Version2.0.4
VanillaforumsVanilla Version2.0.5
VanillaforumsVanilla Version2.0.6
VanillaforumsVanilla Version2.0.7
VanillaforumsVanilla Version2.0.8
VanillaforumsVanilla Version2.0.9
VanillaforumsVanilla Version2.0.10
VanillaforumsVanilla Version2.0.11
VanillaforumsVanilla Version2.0.12
VanillaforumsVanilla Version2.0.13
VanillaforumsVanilla Version2.0.14
VanillaforumsVanilla Version2.0.15
VanillaforumsVanilla Version2.0.16
VanillaforumsVanilla Version2.0.16.1
VanillaforumsVanilla Version2.0.17
VanillaforumsVanilla Version2.0.17.1
VanillaforumsVanilla Version2.0.17.2
VanillaforumsVanilla Version2.0.17.3
VanillaforumsVanilla Version2.0.17.4
VanillaforumsVanilla Version2.0.17.5
VanillaforumsVanilla Version2.0.17.6
VanillaforumsVanilla Version2.0.17.7
VanillaforumsVanilla Version2.0.17.8
VanillaforumsVanilla Version2.0.17.9
VanillaforumsVanilla Version2.0.17.10
VanillaforumsVanilla Version2.0.18
VanillaforumsVanilla Version2.0.18 Updatealpha3
VanillaforumsVanilla Version2.0.18 Updatebeta1
VanillaforumsVanilla Version2.0.18 Updatebeta2
VanillaforumsVanilla Version2.0.18 Updatebeta4
VanillaforumsVanilla Version2.0.18 Updaterc1
VanillaforumsVanilla Version2.0.18 Updaterc2
VanillaforumsVanilla Version2.0.18 Updaterc3
VanillaforumsVanilla Version2.0.18.1
VanillaforumsVanilla Version2.0.18.3
VanillaforumsVanilla Forums Updatea26 Version <= 2.1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.32% 0.515
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 3.5 6.8 2.9
AV:N/AC:M/Au:S/C:N/I:P/A:N