Executive Summary

Informations
Name CVE-2005-1708 First vendor Publication 2005-05-24
Vendor Cve Last vendor Modification 2016-10-18

Security-Database Scoring CVSS v3

Cvss vector : N/A
Overall CVSS Score NA
Base Score NA Environmental Score NA
impact SubScore NA Temporal Score NA
Exploitabality Sub Score NA
 
Calculate full CVSS 3.0 Vectors scores

Security-Database Scoring CVSS v2

Cvss vector : (AV:L/AC:L/Au:N/C:P/I:P/A:P)
Cvss Base Score 4.6 Attack Range Local
Cvss Impact Score 6.4 Attack Complexity Low
Cvss Expoit Score 3.9 Authentication None Required
Calculate full CVSS 2.0 Vectors scores

Detail

templates.admin.users.user_form_processing in Blue Coat Reporter before 7.1.2 allows authenticated users to gain administrator privileges via an HTTP POST that sets volatile.user.administrator to true.

Original Source

Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2005-1708

CAPEC : Common Attack Pattern Enumeration & Classification

Id Name
CAPEC-10 Buffer Overflow via Environment Variables
CAPEC-13 Subverting Environment Variable Values
CAPEC-21 Exploitation of Session Variables, Resource IDs and other Trusted Credentials
CAPEC-31 Accessing/Intercepting/Modifying HTTP Cookies
CAPEC-39 Manipulating Opaque Client-based Data Tokens
CAPEC-45 Buffer Overflow via Symbolic Links
CAPEC-77 Manipulating User-Controlled Variables
CAPEC-274 HTTP Verb Tampering

CWE : Common Weakness Enumeration

% Id Name

Open Source Vulnerability Database (OSVDB)

Id Description
16763 Blue Coat Reporter Admin Account Creation Privilege Escalation

Blue Coat Reporter contains a flaw that may allow a malicious user to gain access to unauthorized privileges. The issue is triggered when a regular user submits a POST request to create a new user with administrative privileges. This flaw may lead to a loss of integrity.

Sources (Detail)

Source Url
BID http://www.securityfocus.com/bid/13723
BUGTRAQ http://marc.info/?l=bugtraq&m=111695726810435&w=2
CONFIRM http://www.bluecoat.com/support/knowledge/advisory_reporter_711_vulnerabiliti...
OSVDB http://www.osvdb.org/16763
SECUNIA http://secunia.com/advisories/15452
VUPEN http://www.vupen.com/english/advisories/2005/0589

Alert History

If you want to see full details history, please login or register.
0
1
2
3
4
5
6
Date Informations
2021-04-22 01:03:14
  • Multiple Updates
2020-05-23 01:36:41
  • Multiple Updates
2020-05-23 00:16:35
  • Multiple Updates
2016-10-18 12:01:41
  • Multiple Updates
2016-06-28 15:18:44
  • Multiple Updates
2016-04-26 13:33:32
  • Multiple Updates
2013-05-11 11:26:17
  • Multiple Updates