CVE-2013-0267

The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nodeAdmin, manageGroup, resourceGrant, or userGrant permissions to gain privileges, cause a denial of service, or conduct cross-site scripting (XSS) attacks by leveraging improper data validation.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:apache:vcl:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:vcl:*:*:*:*:*:*:*:*
cpe:2.3:a:apache:vcl:2.1:*:*:*:*:*:*:*

History

No history.

Information

Published : 2018-02-21 15:29

Updated : 2024-02-04 19:46


NVD link : CVE-2013-0267

Mitre link : CVE-2013-0267

CVE.ORG link : CVE-2013-0267


JSON object : View

Products Affected

apache

  • vcl
CWE
CWE-20

Improper Input Validation

CWE-264

Permissions, Privileges, and Access Controls