CVE-2010-0004

ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:viewvc:viewvc:1.0.8:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.4:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.1:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.5:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.6:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.1.1:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.1.0:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.7:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.1.2:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.3:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.2:*:*:*:*:*:*:*

Information

Published : 2010-01-29 10:30

Updated : 2018-08-13 14:47


NVD link : CVE-2010-0004

Mitre link : CVE-2010-0004


JSON object : View

CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor

Advertisement

dedicated server usa

Products Affected

viewvc

  • viewvc