CVE-2010-2029
 
Severity Score
5.8
*CVSS v2
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
-
*SSVC
Descriptions
Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone.
Cybozu Office 7 Ktai y Dotsales no restringen el acceso a la página de inicio de sesión apropiadamente; lo que permite, a atacantes remotos, evitar la autenticación y obtener o modificar información confidencial a través del ID único del número de telefóno móvil del usuario.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Authentication
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:-
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2010-05-24 CVE Reserved
- 2010-05-24 CVE Published
- 2023-03-07 EPSS Updated
- 2024-08-07 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-264: Permissions, Privileges, and Access Controls
CAPEC
References (7)
URL | Tag | Source |
---|---|---|
http://cybozu.co.jp/products/dl/notice/detail/0034.html | X_refsource_confirm | |
http://jvn.jp/en/jp/JVN87730223/index.html | Third Party Advisory | |
http://jvndb.jvn.jp/ja/contents/2010/JVNDB-2010-000016.html | Third Party Advisory | |
http://www.ipa.go.jp/security/english/vuln/201004_cybozu_en.html | X_refsource_misc | |
http://www.osvdb.org/63933 | Vdb Entry | |
https://exchange.xforce.ibmcloud.com/vulnerabilities/57976 | Vdb Entry |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://secunia.com/advisories/39508 | 2017-08-17 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cybozu Search vendor "Cybozu" | Cybozu Office Search vendor "Cybozu" for product "Cybozu Office" | 7 Search vendor "Cybozu" for product "Cybozu Office" and version "7" | ktai |
Affected
| ||||||
Cybozu Search vendor "Cybozu" | Cybozu Dotsales Search vendor "Cybozu" for product "Cybozu Dotsales" | * | - |
Affected
|