Vulnerability Description
templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bluecoat | Reporter | <= 7.1.1 |
References
- http://marc.info/?l=bugtraq&m=111695726810435&w=2
- http://secunia.com/advisories/15452Vendor Advisory
- http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.Patch
- http://www.osvdb.org/16763
- http://www.securityfocus.com/bid/13723
- http://www.vupen.com/english/advisories/2005/0589
- http://marc.info/?l=bugtraq&m=111695726810435&w=2
- http://secunia.com/advisories/15452Vendor Advisory
- http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabilities.Patch
- http://www.osvdb.org/16763
- http://www.securityfocus.com/bid/13723
- http://www.vupen.com/english/advisories/2005/0589
FAQ
What is CVE-2005-1708?
CVE-2005-1708 is a vulnerability with a CVSS score of 4.6 (MEDIUM). templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true...
How severe is CVE-2005-1708?
CVE-2005-1708 has been rated MEDIUM with a CVSS base score of 4.6/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2005-1708?
Check the references section above for vendor advisories and patch information. Affected products include: Bluecoat Reporter.