CVE-2008-1475

Roundup < 1.4.3 - Unauthenticated Property Permission Bypass via XML-RPC Methods

Title source: llm
STIX 2.1

Description

The xml-rpc server in Roundup 1.4.4 does not check property permissions, which allows attackers to bypass restrictions and edit or read restricted properties via the (1) list, (2) display, and (3) set methods.

References (14)

Core 14
Core References
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/30274
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/28238
Third Party Advisory vendor-advisory x_refsource_gentoo
http://security.gentoo.org/glsa/glsa-200805-21.xml
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29336
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/32805
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/29375
Issue Tracking x_refsource_misc
https://bugzilla.redhat.com/show_bug.cgi?id=436546
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/41240
Third Party Advisory vdb-entry x_refsource_vupen
http://www.vupen.com/english/advisories/2008/0891

Scores

EPSS 0.0174
EPSS Percentile 75.4%

Details

CWE
CWE-264
Status published
Products (37)
pypi/roundup 0 - 1.4.5PyPI
roundup-tracker/roundup 0.1.0
roundup-tracker/roundup 0.1.1
roundup-tracker/roundup 0.1.2
roundup-tracker/roundup 0.1.3
roundup-tracker/roundup 0.2.0
roundup-tracker/roundup 0.2.1
roundup-tracker/roundup 0.2.2
roundup-tracker/roundup 0.2.3
roundup-tracker/roundup 0.2.4
... and 27 more
Published Mar 24, 2008
Tracked Since Feb 18, 2026