CVE-2010-0005

query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.
Severity
UNKNOWN
AV:N/AC:L/Au:N/C:P/I:P/A:P
Atk. Vector
NETWORK
Atk. Complexity
LOW
Base Score
CVSS 3.x
EPSS Score
Percentile: 85%
VendorProductVersion
viewvcviewvc
𝑥
≤ 1.1.2
viewvcviewvc
1.0.1
viewvcviewvc
1.0.2
viewvcviewvc
1.0.3
viewvcviewvc
1.0.4
viewvcviewvc
1.0.5
viewvcviewvc
1.0.6
viewvcviewvc
1.0.7
viewvcviewvc
1.0.8
viewvcviewvc
1.1.0
viewvcviewvc
1.1.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
viewvc
saucy
not-affected
raring
not-affected
quantal
not-affected
precise
not-affected
oneiric
not-affected
natty
not-affected
maverick
not-affected
lucid
ignored
karmic
ignored
jaunty
ignored
intrepid
ignored
hardy
ignored
dapper
dne
Common Weakness Enumeration