Vulnerability Description
ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown impact via activation of a new item, possibly involving addition of arbitrary new content.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Magnolia | Ce | 3.5.1 |
Related Weaknesses (CWE)
References
- http://jira.magnolia.info/browse/MAGNOLIA-2021
- http://secunia.com/advisories/28745Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=573088
- http://www.securityfocus.com/bid/27608
- http://jira.magnolia.info/browse/MAGNOLIA-2021
- http://secunia.com/advisories/28745Vendor Advisory
- http://sourceforge.net/project/shownotes.php?release_id=573088
- http://www.securityfocus.com/bid/27608
FAQ
What is CVE-2008-0701?
CVE-2008-0701 is a vulnerability with a CVSS score of 5.0 (MEDIUM). ActivationHandler in Magnolia CE 3.5.x before 3.5.4 does not check permissions during importing, which allows remote attackers to have an unknown impact via activation of a new item, possibly involvin...
How severe is CVE-2008-0701?
CVE-2008-0701 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2008-0701?
Check the references section above for vendor advisories and patch information. Affected products include: Magnolia Ce.