CVE Database
/

CVE-2008-1292

Back to search

CVE-2008-1292

Published: Mar 24, 2008

Modified: Aug 7, 2024

PUBLISHED

Description

ViewVC before 1.0.5 provides revision metadata without properly checking whether access was intended, which allows remote attackers to obtain sensitive information by reading (1) forbidden pathnames in the revision view, (2) log history that can only be reached by traversing a forbidden object, or (3) forbidden diff view path parameters.

VendorProductVersions

n/a

n/a

affected
n/a

References

GLSA-200803-29
vendor-advisory
x_refsource_GENTOO
29460
third-party-advisory
x_refsource_SECUNIA
29176
third-party-advisory
x_refsource_SECUNIA
ADV-2008-0734
vdb-entry
x_refsource_VUPEN
28055
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now