Back to Database
Status published
Low
CVE-2009-0240
listing.php in WebSVN 2.0 and possibly 1.7 beta, when using...
Vulnerability Description
listing.php in WebSVN 2.0 and possibly 1.7 beta, when using an SVN authz file, allows remote authenticated users to read changelogs or diffs for restricted projects via a modified repname parameter.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2009-0240
Credits & Attribution
No credits recorded in the NVD database.
References
- http://secunia.com/advisories/33945
- http://secunia.com/advisories/34191
- http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=512191
- http://www.gentoo.org/security/en/glsa/glsa-200903-20.xml
- https://exchange.xforce.ibmcloud.com/vulnerabilities/48171
- http://www.openwall.com/lists/oss-security/2009/01/18/2
- http://secunia.com/advisories/32338
- http://www.debian.org/security/2009/dsa-1725
More from tigris
View All →CVE-2010-3199
Untrusted search path vulnerability in TortoiseSVN 1.6.10, Build 19898 and...
Critical
9.3
CVE-2008-5920
The create_anchors function in utils.inc in WebSVN 1.x allows remote...
High
7.5
CVE-2008-5919
Directory traversal vulnerability in rss.php in WebSVN 2.0 and earlier,...
Medium
6.8
CVE-2008-5918
Cross-site scripting (XSS) vulnerability in the getParameterisedSelfUrl function in index.php...
Medium
4.3
Affected Vendor
tigris
View all reports →Affected Software
websvn
Vulnerable Versions:
2.0
Timeline
Official Publish:
January 21st, 2009
Last Modified:
August 7th, 2024
Added to House:
July 19th, 2026
CVSS Vectors
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.