CVE-2013-2318
Published Jun 6, 2013
Last updated 11 years ago
Overview
- Description
- The Content Provider in the MovatwiTouch application before 1.793 and MovatwiTouch Paid application before 1.793 for Android does not properly restrict access to authorization information, which allows attackers to hijack Twitter accounts via a crafted application.
- Source
- vultures@jpcert.or.jp
- NVD status
- Analyzed
Social media
- Hype score
- Not currently trending
Risk scores
CVSS 2.0
- Type
- Primary
- Base score
- 2.6
- Impact score
- 2.9
- Exploitability score
- 4.9
- Vector string
- AV:N/AC:H/Au:N/C:P/I:N/A:N
Weaknesses
- nvd@nist.gov
- CWE-264
Configurations
[ { "nodes": [ { "negate": false, "cpeMatch": [ { "criteria": "cpe:2.3:a:jig:movatwitouch:*:-:*:*:*:android:*:*", "vulnerable": true, "matchCriteriaId": "FCDE8DCB-9254-4656-A686-DE8161B594D7", "versionEndIncluding": "1.792" }, { "criteria": "cpe:2.3:a:jig:movatwitouch_paid:*:-:*:*:*:android:*:*", "vulnerable": true, "matchCriteriaId": "0DB65F4E-8793-4067-88FE-8B7FEE9DE7F4", "versionEndIncluding": "1.792" } ], "operator": "OR" } ] } ]