CVE-2010-0005
29.01.2010, 18:30
query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.Enginsight
| Vendor | Product | Version |
|---|---|---|
| viewvc | viewvc | 𝑥 ≤ 1.1.2 |
| viewvc | viewvc | 1.0.1 |
| viewvc | viewvc | 1.0.2 |
| viewvc | viewvc | 1.0.3 |
| viewvc | viewvc | 1.0.4 |
| viewvc | viewvc | 1.0.5 |
| viewvc | viewvc | 1.0.6 |
| viewvc | viewvc | 1.0.7 |
| viewvc | viewvc | 1.0.8 |
| viewvc | viewvc | 1.1.0 |
| viewvc | viewvc | 1.1.1 |
𝑥
= Vulnerable software versions
Ubuntu Releases
Common Weakness Enumeration
References