« Volver al listado

CVE-2007-1134

Estado: ModificadaAlta (10)—

Unspecified vulnerability in Watchtower (WT) before 0.12 has unknown impact and attack vectors, related to "unauthorized accounts."

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2007-1134",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 10,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:C/I:C/A:C",
          "authentication": "NONE",
          "integrityImpact": "COMPLETE",
          "accessComplexity": "LOW",
          "availabilityImpact": "COMPLETE",
          "confidentialityImpact": "COMPLETE"
        },
        "acInsufInfo": true,
        "impactScore": 10,
        "baseSeverity": "HIGH",
        "obtainAllPrivilege": true,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2007-03-02T21:18:00.000",
  "references": [
    {
      "url": "http://osvdb.org/41106",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://sourceforge.net/project/shownotes.php?release_id=486435&group_id=188798",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/22721",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/0743",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://osvdb.org/41106",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://sourceforge.net/project/shownotes.php?release_id=486435&group_id=188798",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/22721",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2007/0743",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "NVD-CWE-noinfo"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Unspecified vulnerability in Watchtower (WT) before 0.12 has unknown impact and attack vectors, related to \"unauthorized accounts.\""
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad sin especificar en el Watchtower (WT) anterior al 0.12 tiene un impacto desconocido y vectores de ataque, relacionados con \"cuentas sin autorización\"."
    }
  ],
  "lastModified": "2026-06-16T22:37:00.840",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:watchtower:watchtower:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "36AE4A17-9760-458A-9B43-F8290B574375",
              "versionEndIncluding": "0.11"
            },
            {
              "criteria": "cpe:2.3:a:watchtower:watchtower:0.1:alpha:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "67C8F1D4-78D1-487A-8ADE-177ABE39F522"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "evaluatorComment": "Watchtower is prone to an unspecified authentication-bypass vulnerability.\r\n\r\nAn attacker can exploit this issue to gain unauthorized access to the application.\r\n\r\nVersions prior to 0.12 are vulnerable. \r\n \r\nhttp://www.securityfocus.com/bid/22721/info",
  "sourceIdentifier": "cve@mitre.org",
  "evaluatorSolution": "The vendor has released version 0.12 to address this issue.  \r\n\r\n\r\nDownload: http://downloads.sourceforge.net/wtelements/wt0.12.tar.gz?modtime=1171 460836&big_mirror=0\r\n"
}