CVE Vulnerabilities

CVE-2012-4954

Published: Nov 15, 2012 | Modified: Jun 04, 2020
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
3.5 LOW
AV:N/AC:M/Au:S/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu

The edit-profile page in Vanilla Forums before 2.1a32 allows remote authenticated users to modify arbitrary profile settings by replacing the UserID value during a man-in-the-middle attack, related to a parameter manipulation issue.

Affected Software

Name Vendor Start Version End Version
Vanilla Vanillaforums * 2.0.18.4 (including)
Vanilla Vanillaforums 2.0.0 (including) 2.0.0 (including)
Vanilla Vanillaforums 2.0.1 (including) 2.0.1 (including)
Vanilla Vanillaforums 2.0.2 (including) 2.0.2 (including)
Vanilla Vanillaforums 2.0.3 (including) 2.0.3 (including)
Vanilla Vanillaforums 2.0.4 (including) 2.0.4 (including)
Vanilla Vanillaforums 2.0.5 (including) 2.0.5 (including)
Vanilla Vanillaforums 2.0.6 (including) 2.0.6 (including)
Vanilla Vanillaforums 2.0.7 (including) 2.0.7 (including)
Vanilla Vanillaforums 2.0.8 (including) 2.0.8 (including)
Vanilla Vanillaforums 2.0.9 (including) 2.0.9 (including)
Vanilla Vanillaforums 2.0.10 (including) 2.0.10 (including)
Vanilla Vanillaforums 2.0.11 (including) 2.0.11 (including)
Vanilla Vanillaforums 2.0.12 (including) 2.0.12 (including)
Vanilla Vanillaforums 2.0.13 (including) 2.0.13 (including)
Vanilla Vanillaforums 2.0.14 (including) 2.0.14 (including)
Vanilla Vanillaforums 2.0.15 (including) 2.0.15 (including)
Vanilla Vanillaforums 2.0.16 (including) 2.0.16 (including)
Vanilla Vanillaforums 2.0.16.1 (including) 2.0.16.1 (including)
Vanilla Vanillaforums 2.0.17 (including) 2.0.17 (including)
Vanilla Vanillaforums 2.0.17.1 (including) 2.0.17.1 (including)
Vanilla Vanillaforums 2.0.17.2 (including) 2.0.17.2 (including)
Vanilla Vanillaforums 2.0.17.3 (including) 2.0.17.3 (including)
Vanilla Vanillaforums 2.0.17.4 (including) 2.0.17.4 (including)
Vanilla Vanillaforums 2.0.17.5 (including) 2.0.17.5 (including)
Vanilla Vanillaforums 2.0.17.6 (including) 2.0.17.6 (including)
Vanilla Vanillaforums 2.0.17.7 (including) 2.0.17.7 (including)
Vanilla Vanillaforums 2.0.17.8 (including) 2.0.17.8 (including)
Vanilla Vanillaforums 2.0.17.9 (including) 2.0.17.9 (including)
Vanilla Vanillaforums 2.0.17.10 (including) 2.0.17.10 (including)
Vanilla Vanillaforums 2.0.18 (including) 2.0.18 (including)
Vanilla Vanillaforums 2.0.18-alpha3 (including) 2.0.18-alpha3 (including)
Vanilla Vanillaforums 2.0.18-beta1 (including) 2.0.18-beta1 (including)
Vanilla Vanillaforums 2.0.18-beta2 (including) 2.0.18-beta2 (including)
Vanilla Vanillaforums 2.0.18-beta4 (including) 2.0.18-beta4 (including)
Vanilla Vanillaforums 2.0.18-rc1 (including) 2.0.18-rc1 (including)
Vanilla Vanillaforums 2.0.18-rc2 (including) 2.0.18-rc2 (including)
Vanilla Vanillaforums 2.0.18-rc3 (including) 2.0.18-rc3 (including)
Vanilla Vanillaforums 2.0.18.1 (including) 2.0.18.1 (including)
Vanilla Vanillaforums 2.0.18.3 (including) 2.0.18.3 (including)
Vanilla_forums Vanillaforums * 2.1 (including)

References