CVE Vulnerabilities

CVE-2016-7903

Published: Jan 04, 2017 | Modified: Jan 07, 2017
CVSS 3.x
3.7
LOW
Source:
NVD
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW

Dotclear before 2.10.3, when the Host header is not part of the web server routing process, allows remote attackers to modify the password reset address link via the HTTP Host header.

Affected Software

Name Vendor Start Version End Version
Dotclear Dotclear * 2.10.2 (including)
Dotclear Ubuntu esm-apps/xenial *
Dotclear Ubuntu precise *
Dotclear Ubuntu trusty *
Dotclear Ubuntu xenial *

References