Stampit Web uses guessable id values for online stamp purchases, which allows remote attackers to cause a denial of service (stamp invalidation) via a SOAP request with an id value for a stamp that has not yet been printed.
References
Configurations
History
21 Nov 2024, 00:34
Type | Values Removed | Values Added |
---|---|---|
References | () http://seclists.org/fulldisclosure/2007/Aug/0441.html - | |
References | () http://securityreason.com/securityalert/3129 - | |
References | () https://exchange.xforce.ibmcloud.com/vulnerabilities/36365 - | |
References | () https://www.cynops.de/advisories/CVE-2007-3871-signed.txt - | |
References | () https://www.cynops.de/advisories/CVE-2007-3871.txt - | |
References | () https://www.klink.name/security/aklink-sa-2007-003-stampit-web-dos.txt - |
Information
Published : 2007-09-12 19:17
Updated : 2024-11-21 00:34
NVD link : CVE-2007-3871
Mitre link : CVE-2007-3871
CVE.ORG link : CVE-2007-3871
JSON object : View
Products Affected
deutsche_post
- stampit_web
CWE