Show filters
3 Total Results
Displaying 1-3 of 3
Sort by:
Attacker Value
Unknown

CVE-2012-3356

Disclosure Date: July 22, 2012 (last updated October 04, 2023)
The remote SVN views functionality (lib/vclib/svn/svn_ra.py) in ViewVC before 1.1.15 does not properly perform authorization, which allows remote attackers to bypass intended access restrictions via unspecified vectors.
0
Attacker Value
Unknown

CVE-2012-3357

Disclosure Date: July 22, 2012 (last updated October 04, 2023)
The SVN revision view (lib/vclib/svn/svn_repos.py) in ViewVC before 1.1.15 does not properly handle log messages when a readable path is copied from an unreadable path, which allows remote attackers to obtain sensitive information, related to a "log msg leak."
0
Attacker Value
Unknown

CVE-2009-5024

Disclosure Date: May 23, 2011 (last updated October 04, 2023)
ViewVC before 1.1.11 allows remote attackers to bypass the cvsdb row_limit configuration setting, and consequently conduct resource-consumption attacks, via the limit parameter, as demonstrated by a "query revision history" request.
0