Stampit Web uses guessable id values for online stamp purchases, which allows remote attackers to cause a denial of service (stamp invalidation) via a SOAP request with an id value for a stamp that has not yet been printed.
References
Configurations
History
No history.
Information
Published : 2007-09-12 19:17
Updated : 2024-02-28 11:01
NVD link : CVE-2007-3871
Mitre link : CVE-2007-3871
CVE.ORG link : CVE-2007-3871
JSON object : View
Products Affected
deutsche_post
- stampit_web
CWE