MEDIUM · 4.0

CVE-2007-3256

Xythos Enterprise Document Manager (XEDM), Digital Locker (XDL), and possibly WebFile Server before 6.0.46.1 allow remote authenticated users to associate arbitrary Content-Type HTTP headers with docu...

Vulnerability Description

Xythos Enterprise Document Manager (XEDM), Digital Locker (XDL), and possibly WebFile Server before 6.0.46.1 allow remote authenticated users to associate arbitrary Content-Type HTTP headers with documents, which might facilitate malware distribution.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
XythosDigital Locker<= 6.0.46.0
XythosEnterprise Document Manager<= 6.0.46.0
XythosWebfile Server<= 6.0.46.0

References

FAQ

What is CVE-2007-3256?

CVE-2007-3256 is a vulnerability with a CVSS score of 4.0 (MEDIUM). Xythos Enterprise Document Manager (XEDM), Digital Locker (XDL), and possibly WebFile Server before 6.0.46.1 allow remote authenticated users to associate arbitrary Content-Type HTTP headers with docu...

How severe is CVE-2007-3256?

CVE-2007-3256 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3256?

Check the references section above for vendor advisories and patch information. Affected products include: Xythos Digital Locker, Xythos Enterprise Document Manager, Xythos Webfile Server.