CVE-2007-2448
CVE-2007-2448
Subversion 1.4.3 and earlier does not properly implement the "partial access" privilege for users who have access to changed paths but not copied paths, which allows remote authenticated users to obtain sensitive information (revision properties) via svn (1) propget, (2) proplist, or (3) propedit.
Produtos afetados
n/a · n/aQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →Referências
http://osvdb.org/36070http://secunia.com/advisories/43139http://securitytracker.com/id?1018237https://issues.rpath.com/browse/RPL-1896http://subversion.tigris.org/security/CVE-2007-2448-advisory.txthttp://www.securityfocus.com/bid/24463http://www.ubuntu.com/usn/USN-1053-1http://www.vupen.com/english/advisories/2007/2230http://www.vupen.com/english/advisories/2011/0264