CVE-2012-3473
Published Aug 12, 2012
Last updated 12 years ago
Overview
- Description
- The (1) reports API and (2) administration feature in the comments API in the Ushahidi Platform before 2.5 do not require authentication, which allows remote attackers to generate reports and organize comments via API functions.
- Source
- secalert@redhat.com
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 6.4
- Impact score
- 4.9
- Exploitability score
- 10
- Vector string
- AV:N/AC:L/Au:N/C:P/I:P/A:N
Weaknesses
- nvd@nist.gov
- CWE-287
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:*:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "984B26E4-C672-46DF-B26B-8CAAEDBDFEB0", "versionEndIncluding": "2.4.1" }, { "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:1.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "86468BDD-17C2-49CC-A488-F38CC8630979" }, { "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:1.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "E8EBC5A6-4FB0-4385-8299-5D6298977534" }, { "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.0:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "826225E4-F4F8-4FB6-AFAF-23CD6720CE5E" }, { "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "6754F1ED-E827-433C-8F50-71F04293EEB1" }, { "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "7B1BC250-09BC-4051-ABEE-8B8FE1558279" }, { "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.2.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "5D260CD2-5483-48D2-87B9-C0298F5F2B23" }, { "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.3.1:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "489F7397-CF33-42C5-AF46-956D5692C6D1" }, { "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.3.2:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "B1C84D59-409A-4E73-A65A-8B12594B61DF" }, { "criteria": "cpe:2.3:a:ushahidi:ushahidi_platform:2.4:*:*:*:*:*:*:*", "vulnerable": true, "matchCriteriaId": "8A004E65-AFA7-4551-BA2B-8EF9450B0684" } ], "operator": "OR" } ] } ]