CVE-2013-0267

Severity CVSS v4.0:
Pending analysis
Type:
CWE-20 Input Validation
Publication date:
21/02/2018
Last modified:
07/11/2023

Description

The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nodeAdmin, manageGroup, resourceGrant, or userGrant permissions to gain privileges, cause a denial of service, or conduct cross-site scripting (XSS) attacks by leveraging improper data validation.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:apache:vcl:*:*:*:*:*:*:*:* 2.2 (including) 2.2.2 (including)
cpe:2.3:a:apache:vcl:*:*:*:*:*:*:*:* 2.3 (including) 2.3.2 (excluding)
cpe:2.3:a:apache:vcl:2.1:*:*:*:*:*:*:*