CVE-2010-2029
Published May 24, 2010
Last updated 7 years ago
Overview
- Description
- Cybozu Office 7 Ktai and Dotsales do not properly restrict access to the login page, which allows remote attackers to bypass authentication and obtain or modify sensitive information by using the unique ID of the user's cell phone.
- Source
- cve@mitre.org
- NVD status
- Modified
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 5.8
- Impact score
- 4.9
- Exploitability score
- 8.6
- Vector string
- AV:N/AC:M/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cybozu:cybozu_office:7:-:ktai:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "941E9A1B-1510-4AE1-9E56-5EF33EC9104A" } ], "operator": "OR" } ] }, { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:cybozu:cybozu_dotsales:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "313EE48E-33E5-4363-9394-762887056DCA" } ], "operator": "OR" } ] } ]