WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration, and (3) the Image Uploader, which has unknown impact and attack vectors.
Link | Tags |
---|---|
http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=250 | patch vendor advisory |
http://www.vupen.com/english/advisories/2007/0604 | vdb entry |
http://osvdb.org/33282 | vdb entry |
http://osvdb.org/33279 | vdb entry |
http://secunia.com/advisories/24080 | third party advisory |
http://www.securityfocus.com/bid/22563 | vdb entry |