Secunia Logo  


Secunia PSI WorldMap
 
CVE Reference: CVE-2008-1475
NOTE: The text on this page is written by CVE MITRE and reflects neither the opinions of Secunia or the results of our research. All data on this page is written and maintained by CVE MITRE.

Original Page at CVE MITRE:
CVE-2008-1475

Description:
The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.

CVE Status:
Candidate

References:

XF
  http://xforce.iss.net/xforce/xfdb/41240

SAID
  Secunia Advisory: SA32805
  Secunia Advisory: SA29336
  Secunia Advisory: SA29375
  Secunia Advisory: SA30274

MISC

GENTOO
  http://security.gentoo.org/glsa/glsa-200805-21.xml

FEDORA

CONFIRM
  http://sourceforge.net/tracker/index.php?func=detail&aid=1907211&group_id=31577&atid=402788

BID
  28238


Return to the previous page.