CVE-2010-0005

EUVD-2010-0037
query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:P/A:P
Base Score
CVSS 3.x
EPSS Score
Percentile: 64%
Affected Products (NVD)
VendorProductVersion
viewvcviewvc
𝑥
≤ 1.1.2
viewvcviewvc
1.0.1
viewvcviewvc
1.0.2
viewvcviewvc
1.0.3
viewvcviewvc
1.0.4
viewvcviewvc
1.0.5
viewvcviewvc
1.0.6
viewvcviewvc
1.0.7
viewvcviewvc
1.0.8
viewvcviewvc
1.1.0
viewvcviewvc
1.1.1
𝑥
= Vulnerable software versions
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
viewvc
dapper
dne
hardy
ignored
intrepid
ignored
jaunty
ignored
karmic
ignored
lucid
ignored
maverick
not-affected
natty
not-affected
oneiric
not-affected
precise
not-affected
quantal
not-affected
raring
not-affected
saucy
not-affected
Common Weakness Enumeration