CVE-2008-5184

The web interface (cgi-bin/admin.c) in CUPS before 1.3.8 uses the guest username when a user is not logged on to the web server, which makes it easier for remote attackers to bypass intended policy and conduct CSRF attacks via the (1) add and (2) cancel RSS subscription functions.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
10 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:C/I:C/A:C
canonicalCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 51%
VendorProductVersion
applecups
𝑥
≤ 1.3.7
applecups
1.1
applecups
1.1.1
applecups
1.1.2
applecups
1.1.3
applecups
1.1.4
applecups
1.1.5
applecups
1.1.5-1
applecups
1.1.5-2
applecups
1.1.6
applecups
1.1.6-1
applecups
1.1.6-2
applecups
1.1.6-3
applecups
1.1.7
applecups
1.1.8
applecups
1.1.9
applecups
1.1.9-1
applecups
1.1.10
applecups
1.1.10-1
applecups
1.1.11
applecups
1.1.12
applecups
1.1.13
applecups
1.1.14
applecups
1.1.15
applecups
1.1.16
applecups
1.1.17
applecups
1.1.18
applecups
1.1.19
applecups
1.1.19:rc1
applecups
1.1.19:rc2
applecups
1.1.19:rc3
applecups
1.1.19:rc4
applecups
1.1.19:rc5
applecups
1.1.20
applecups
1.1.20:rc1
applecups
1.1.20:rc2
applecups
1.1.20:rc3
applecups
1.1.20:rc4
applecups
1.1.20:rc5
applecups
1.1.20:rc6
applecups
1.1.21
applecups
1.1.21:rc1
applecups
1.1.21:rc2
applecups
1.1.22
applecups
1.1.22:rc1
applecups
1.1.22:rc2
applecups
1.1.23
applecups
1.1.23:rc1
applecups
1.2:b1
applecups
1.2:b2
applecups
1.2:rc1
applecups
1.2:rc2
applecups
1.2:rc3
applecups
1.2.0
applecups
1.2.1
applecups
1.2.2
applecups
1.2.3
applecups
1.2.4
applecups
1.2.5
applecups
1.2.6
applecups
1.2.7
applecups
1.2.8
applecups
1.2.9
applecups
1.2.10
applecups
1.2.11
applecups
1.2.12
applecups
1.3:b1
applecups
1.3:rc1
applecups
1.3:rc2
applecups
1.3.0
applecups
1.3.1
applecups
1.3.2
applecups
1.3.3
applecups
1.3.4
applecups
1.3.5
applecups
1.3.6
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
cups
bullseye
2.3.3op2-3+deb11u8
fixed
etch
not-affected
bullseye (security)
2.3.3op2-3+deb11u9
fixed
bookworm
2.4.2-3+deb12u7
fixed
bookworm (security)
2.4.2-3+deb12u8
fixed
sid
2.4.10-2
fixed
trixie
2.4.10-2
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
cups
intrepid
not-affected
hardy
dne
gutsy
dne
dapper
dne
cupsys
intrepid
dne
hardy
Fixed 1.3.7-1ubuntu3.3
released
gutsy
Fixed 1.3.2-1ubuntu7.9
released
dapper
not-affected
Common Weakness Enumeration