CVE-2007-2233
Published Apr 25, 2007
Last updated 6 years ago
Overview
- Description
- cosign-bin/cosign.cgi in Cosign 2.0.2 and earlier allows remote authenticated users to perform unauthorized actions as an arbitrary user by using CR (\r) sequences in the service parameter to inject LOGIN and REGISTER commands with the desired username.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.5
- Impact score
- 6.4
- Exploitability score
- 8
- Vector string
- AV:N/AC:L/Au:S/C:P/I:P/A:P
Weaknesses
- nvd@nist.gov
- NVD-CWE-Other
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cosign:cosign:0.7.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E23AF2A1-E5CC-47D1-836A-D70559450C2D" }, { "criteria": "cpe:2.3:a:cosign:cosign:0.8.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "830BB297-8A02-4217-8D6F-16A3B06C699B" }, { "criteria": "cpe:2.3:a:cosign:cosign:0.9.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "BD7EC94A-E855-44F7-9319-A12F1533B9AC" }, { "criteria": "cpe:2.3:a:cosign:cosign:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "63260012-4D2C-484A-B21B-D8AE3997EC29" }, { "criteria": "cpe:2.3:a:cosign:cosign:1.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "A0B5649F-D363-4BAF-AEA8-5680A247A746" }, { "criteria": "cpe:2.3:a:cosign:cosign:1.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B1AC70B-943D-49ED-8E2F-11675B6D4161" }, { "criteria": "cpe:2.3:a:cosign:cosign:1.6:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "3E770DD1-CDBE-4EBB-A4A0-0CAB146B8873" }, { "criteria": "cpe:2.3:a:cosign:cosign:1.7:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "99956D6A-83B2-495D-89FE-9AD5081306BC" }, { "criteria": "cpe:2.3:a:cosign:cosign:1.8:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1CE75FF8-FD5E-436A-BFB4-A86323C72865" }, { "criteria": "cpe:2.3:a:cosign:cosign:1.8.5:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "1B2B5E34-D0D3-4D55-8798-557E84EEA690" }, { "criteria": "cpe:2.3:a:cosign:cosign:1.9:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "0429B143-D667-4E2B-9057-EA332FE57447" }, { "criteria": "cpe:2.3:a:cosign:cosign:2.0.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B1D12776-9B76-4349-B539-453B77A25E28" }, { "criteria": "cpe:2.3:a:cosign:cosign:2.0.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "AB58EBCD-077C-42DA-8BA9-742D917DD4F7" } ], "operator": "OR" } ] } ]