PT-2010-1817 · Turbogears · Turbogears2

Mark Ramm-Christensen

·

Publicado

2010-11-05

·

Atualizado

2010-11-09

·

CVE-2009-5015

CVSS v2.0

7.5

Alta

VetorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions TurboGears2 versions prior to 2.0.2
Description The issue in TurboGears2 concerns the URL dispatch mechanism, which exposes controller methods even when an @expose decoration is not used. This has an unspecified impact and attack vectors.
Recommendations For versions prior to 2.0.2, update to version 2.0.2 or later to resolve the issue.

Correção

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Identificadores relacionados

CVE-2009-5015

Produtos afetados

Turbogears2