CVE-2007-5113

report.cgi in Google Urchin allows remote attackers to bypass authentication and obtain sensitive information (web server logs) via certain modified query parameters, as demonstrated using the profile, rid, prefs, n, vid, bd, ed, dt, and gtype parameters, a different vulnerability than CVE-2007-5112.
Configurations

Configuration 1 (hide)

cpe:2.3:a:roi_revolution:urchin:*:*:*:*:*:*:*:*

History

21 Nov 2024, 00:37

Type Values Removed Values Added
References () http://ha.ckers.org/blog/20070823/xss-and-possible-information-disclosure-in-urchin/ - () http://ha.ckers.org/blog/20070823/xss-and-possible-information-disclosure-in-urchin/ -
References () http://securityvulns.ru/Sdocument90.html - () http://securityvulns.ru/Sdocument90.html -
References () http://websecurity.com.ua/1283/ - () http://websecurity.com.ua/1283/ -
References () http://www.securityfocus.com/archive/1/482006/100/0/threaded - () http://www.securityfocus.com/archive/1/482006/100/0/threaded -
References () http://www.securityfocus.com/bid/26037 - () http://www.securityfocus.com/bid/26037 -

Information

Published : 2007-09-26 23:17

Updated : 2024-11-21 00:37


NVD link : CVE-2007-5113

Mitre link : CVE-2007-5113

CVE.ORG link : CVE-2007-5113


JSON object : View

Products Affected

roi_revolution

  • urchin
CWE
CWE-287

Improper Authentication