CVE-2008-1291
 
Severity Score
4.3
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
ViewVC before 1.0.5 stores sensitive information under the web root with insufficient access control, which allows remote attackers to read files and list folders under the hidden CVSROOT folder.
ViewVC before 1.0.5 almacena información sensible bajo la raíz web con un control de acceso insuficiente, lo que permite a atacantes remotos leer archivos y listar carpetas bajo la carpeta oculta CVSROOT.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2008-03-12 CVE Reserved
- 2008-03-19 CVE Published
- 2024-08-07 CVE Updated
- 2024-11-11 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
CAPEC
References (8)
URL | Tag | Source |
---|---|---|
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=471380 | X_refsource_confirm | |
http://bugs.gentoo.org/show_bug.cgi?id=212288 | X_refsource_confirm | |
http://viewvc.tigris.org/source/browse/viewvc/trunk/CHANGES?rev=HEAD | X_refsource_confirm | |
http://www.vupen.com/english/advisories/2008/0734/references | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://www.securityfocus.com/bid/28055 | 2009-08-20 |
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/29176 | 2009-08-20 | |
http://secunia.com/advisories/29460 | 2009-08-20 | |
http://security.gentoo.org/glsa/glsa-200803-29.xml | 2009-08-20 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Viewvc Search vendor "Viewvc" | Viewvc Search vendor "Viewvc" for product "Viewvc" | 1.0.2 Search vendor "Viewvc" for product "Viewvc" and version "1.0.2" | - |
Affected
| in | Gentoo Search vendor "Gentoo" | Linux Search vendor "Gentoo" for product "Linux" | * | - |
Safe
|
Viewvc Search vendor "Viewvc" | Viewvc Search vendor "Viewvc" for product "Viewvc" | 1.0.2 Search vendor "Viewvc" for product "Viewvc" and version "1.0.2" | - |
Affected
| in | Redhat Search vendor "Redhat" | Fedora Search vendor "Redhat" for product "Fedora" | 7 Search vendor "Redhat" for product "Fedora" and version "7" | - |
Safe
|
Viewvc Search vendor "Viewvc" | Viewvc Search vendor "Viewvc" for product "Viewvc" | 1.0.2 Search vendor "Viewvc" for product "Viewvc" and version "1.0.2" | - |
Affected
| in | Redhat Search vendor "Redhat" | Fedora Search vendor "Redhat" for product "Fedora" | 8 Search vendor "Redhat" for product "Fedora" and version "8" | - |
Safe
|
Viewvc Search vendor "Viewvc" | Viewvc Search vendor "Viewvc" for product "Viewvc" | 1.0.3 Search vendor "Viewvc" for product "Viewvc" and version "1.0.3" | - |
Affected
| in | Gentoo Search vendor "Gentoo" | Linux Search vendor "Gentoo" for product "Linux" | * | - |
Safe
|
Viewvc Search vendor "Viewvc" | Viewvc Search vendor "Viewvc" for product "Viewvc" | 1.0.3 Search vendor "Viewvc" for product "Viewvc" and version "1.0.3" | - |
Affected
| in | Redhat Search vendor "Redhat" | Fedora Search vendor "Redhat" for product "Fedora" | 7 Search vendor "Redhat" for product "Fedora" and version "7" | - |
Safe
|
Viewvc Search vendor "Viewvc" | Viewvc Search vendor "Viewvc" for product "Viewvc" | 1.0.3 Search vendor "Viewvc" for product "Viewvc" and version "1.0.3" | - |
Affected
| in | Redhat Search vendor "Redhat" | Fedora Search vendor "Redhat" for product "Fedora" | 8 Search vendor "Redhat" for product "Fedora" and version "8" | - |
Safe
|