The DAV component in Chandler Server (Cosmo) before 0.10.1 does not check resource creation permissions, which allows remote authenticated users to create arbitrary resources in another user's home collection.
References
Configurations
History
21 Nov 2024, 00:40
Type | Values Removed | Values Added |
---|---|---|
References | () http://lists.osafoundation.org/pipermail/cosmo-dev/2007-December/005442.html - | |
References | () http://osvdb.org/44152 - | |
References | () http://www.vupen.com/english/advisories/2007/4214 - | |
References | () https://bugzilla.osafoundation.org/show_bug.cgi?id=11587 - |
Information
Published : 2007-12-15 02:46
Updated : 2024-11-21 00:40
NVD link : CVE-2007-6383
Mitre link : CVE-2007-6383
CVE.ORG link : CVE-2007-6383
JSON object : View
Products Affected
chandler_project
- chandler_server
CWE
CWE-264
Permissions, Privileges, and Access Controls