CVE Vulnerabilities

CVE-2007-4888

Published: Sep 14, 2007 | Modified: Nov 15, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

The You are not allowed… error handler in XWiki 1.0 B1 and 1.0 B2 associates the doc variable with the entire document content and metadata regardless of a users view rights, which allows remote authenticated users to read arbitrary documents via a custom skin that prints the content attribute of the doc variable.

Affected Software

Name Vendor Start Version End Version
Xwiki Xwiki 1.0_b1 (including) 1.0_b1 (including)
Xwiki Xwiki 1.0_b2 (including) 1.0_b2 (including)

References