CVE-2007-1489
Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin access by modifying cookies and performing "certain consecutive actions," possibly due to a cross-site request forgery…
Does this matter?
Lower severity and a low EPSS score (0.67%). Track it; it rarely justifies an emergency change on its own.
Description
Unspecified vulnerability in web-app.org Web Automated Perl Portal (WebAPP) 0.9.9.4 to 0.9.9.6 allows remote attackers to obtain admin access by modifying cookies and performing "certain consecutive actions," possibly due to a cross-site request forgery (CSRF) vulnerability.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 0.67% probability · 50th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-352
- Affected
- web-app.org/webapp
- Source
- cve@mitre.org
References
- http://osvdb.org/33273
- http://secunia.com/advisories/24540Vendor Advisory
- http://www.attrition.org/pipermail/vim/2007-March/001446.html
- http://www.web-app.org/cgi-bin/index.cgi?action=downloadinfo&cat=crip&id=2Patch
- http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=256
- http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=259
- http://osvdb.org/33273
- http://secunia.com/advisories/24540Vendor Advisory
- http://www.attrition.org/pipermail/vim/2007-March/001446.html
- http://www.web-app.org/cgi-bin/index.cgi?action=downloadinfo&cat=crip&id=2Patch
- http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=256
- http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=259
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.