CVE Database
/

CVE-2007-3255

Back to search

CVE-2007-3255

Published: Jun 27, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Multiple cross-site request forgery (CSRF) vulnerabilities in Xythos Enterprise Document Manager (XEDM) before 5.0.25.8, and 6.x before 6.0.46.1, allow remote authenticated users to execute commands as arbitrary users via (1) a saved Workflow name or (2) the Content-Type HTTP header. NOTE: item 2 also affects the same version numbers of Xythos Digital Locker (XDL). One or both vectors might also affect Xythos WebFile Server.

VendorProductVersions

n/a

n/a

affected
n/a

References

24521
vdb-entry
x_refsource_BID
37616
vdb-entry
x_refsource_OSVDB
25783
third-party-advisory
x_refsource_SECUNIA
1018292
vdb-entry
x_refsource_SECTRACK
xedm-multiple-csrf(35084)
vdb-entry
x_refsource_XF
2845
third-party-advisory
x_refsource_SREASON
1018291
vdb-entry
x_refsource_SECTRACK
37615
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now