Show filters
13 Total Results
Displaying 1-10 of 13
Sort by:
Attacker Value
Unknown

CVE-2007-5743

Disclosure Date: November 07, 2019 (last updated November 27, 2024)
viewvc 1.0.3 allows improper access control to files in a repository when using the "forbidden" configuration option.
Attacker Value
Unknown

CVE-2012-3356

Disclosure Date: July 22, 2012 (last updated October 04, 2023)
The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-3357

Disclosure Date: July 22, 2012 (last updated October 04, 2023)
The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers to obtain sensitive information, related to a "log msg leak."
0
Attacker Value
Unknown

CVE-2009-5024

Disclosure Date: May 23, 2011 (last updated October 04, 2023)
ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a "query revision history" request.
0
Attacker Value
Unknown

CVE-2010-0132

Disclosure Date: March 31, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in ViewVC 1.1 before 1.1.5 and 1.0 before 1.0.11, when the regular expression search functionality is enabled, allows remote attackers to inject arbitrary web script or HTML via vectors related to "search_re input," a different vulnerability than CVE-2010-0736.
0
Attacker Value
Unknown

CVE-2010-0736

Disclosure Date: March 19, 2010 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in the view_queryform function in lib/viewvc.py in ViewVC before 1.0.10, and 1.1.x before 1.1.4, allows remote attackers to inject arbitrary web script or HTML via "user-provided input."
0
Attacker Value
Unknown

CVE-2010-0005

Disclosure Date: January 29, 2010 (last updated October 04, 2023)
query.py in the query interface in ViewVC before 1.1.3 does not reject configurations that specify an unsupported authorizer for a root, which might allow remote attackers to bypass intended access restrictions via a query.
0
Attacker Value
Unknown

CVE-2010-0004

Disclosure Date: January 29, 2010 (last updated October 04, 2023)
ViewVC before 1.1.3 composes the root listing view without using the authorizer for each root, which might allow remote attackers to discover private root names by reading this view.
0
Attacker Value
Unknown

CVE-2009-3619

Disclosure Date: November 10, 2009 (last updated October 04, 2023)
Unspecified vulnerability in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 has unknown impact and remote attack vectors related to "printing illegal parameter names and values."
0
Attacker Value
Unknown

CVE-2009-3618

Disclosure Date: November 10, 2009 (last updated October 04, 2023)
Cross-site scripting (XSS) vulnerability in viewvc.py in ViewVC 1.0 before 1.0.9 and 1.1 before 1.1.2 allows remote attackers to inject arbitrary web script or HTML via the view parameter. NOTE: some of these details are obtained from third party information.
0