Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2013-0267


The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nodeAdmin, manageGroup, resourceGrant, or userGrant permissions to gain privileges, cause a denial of service, or conduct cross-site scripting (XSS) attacks by leveraging improper data validation.


Published

2018-02-21T15:29:00.213

Last Modified

2024-11-21T01:47:11.697

Status

Modified

Source

[email protected]

Severity

CVSSv3.0: 8.8 (HIGH)

CVSSv2 Vector

AV:N/AC:L/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: LOW
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

8.0

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-20
    CWE-264

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application apache vcl ≤ 2.2.2 Yes
Application apache vcl < 2.3.2 Yes
Application apache vcl 2.1 Yes

References