CVE-2008-1290

ViewVC before 1.0.5 includes "all-forbidden" files within search results that list CVS or Subversion (SVN) commits, which allows remote attackers to obtain sensitive information.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:o:gentoo:linux:*:*:*:*:*:*:*:*
cpe:2.3:o:redhat:fedora:7:*:*:*:*:*:*:*
cpe:2.3:o:redhat:fedora:8:*:*:*:*:*:*:*
OR cpe:2.3:a:viewvc:viewvc:1.0.2:*:*:*:*:*:*:*
cpe:2.3:a:viewvc:viewvc:1.0.3:*:*:*:*:*:*:*

History

No history.

Information

Published : 2008-03-24 17:44

Updated : 2023-12-10 10:51


NVD link : CVE-2008-1290

Mitre link : CVE-2008-1290

CVE.ORG link : CVE-2008-1290


JSON object : View

Products Affected

viewvc

  • viewvc

redhat

  • fedora

gentoo

  • linux
CWE
CWE-200

Exposure of Sensitive Information to an Unauthorized Actor