PT-2007-3957 · Efilecabinet · Efilecabinet

Published

2007-05-13

·

Updated

2018-10-16

·

CVE-2007-2638

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions eFileCabinet version 3.3
Description The issue allows remote attackers to bypass authentication and access restricted portions of the interface via an invalid filecabinetnumber. This can be leveraged to obtain sensitive information or create new data structures.
Recommendations For eFileCabinet version 3.3, consider restricting access to the interface until a fix is available, and avoid using invalid filecabinetnumber values to prevent exploitation. At the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2007-2638

Affected Products

Efilecabinet