CVE-2007-4240 (CNNVD-200708-128)
中文标题:
Help Center Live Administration 多个安全绕过漏洞
英文标题:
The check_logout function in class/auth.php in Help Center Live (hcl) 2.1.3a sends a redirect to the...
漏洞描述
中文描述:
Help Center Live (hcl) 2.1.3a版本的class/auth.php中的check_logout函数发送一个对网络浏览器的直接请求,但没有在管理证书遗失的时候退出程序,远程攻击者可以借助对(1) admin/departments.php, (2) admin/operators.php, 以及其它未明脚本的特定请求,删除管理用户并具有未明影响。
英文描述:
The check_logout function in class/auth.php in Help Center Live (hcl) 2.1.3a sends a redirect to the web browser but does not exit when administrative credentials are missing, which allows remote attackers to delete administrative users and have other unspecified impact via certain requests to (1) admin/departments.php, (2) admin/operators.php, and other unspecified scripts. NOTE: some of these details are obtained from third party information.
CWE类型:
标签:
受影响产品
| 厂商 | 产品 | 版本 | 版本范围 | 平台 | CPE |
|---|---|---|---|---|---|
| help_center_live | help_center_live | 2.1.3a | - | - |
cpe:2.3:a:help_center_live:help_center_live:2.1.3a:*:*:*:*:*:*:*
|
解决方案
中文解决方案:
英文解决方案:
临时解决方案:
CVSS评分详情
AV:N/AC:L/Au:N/C:P/I:P/A:P
时间信息
利用信息
数据源详情
| 数据源 | 记录ID | 版本 | 提取时间 |
|---|---|---|---|
| CVE | cve_CVE-2007-4240 |
2025-11-11 15:17:54 | 2025-11-11 07:32:46 |
| NVD | nvd_CVE-2007-4240 |
2025-11-11 14:52:11 | 2025-11-11 07:41:32 |
| CNNVD | cnnvd_CNNVD-200708-128 |
2025-11-11 15:08:58 | 2025-11-11 07:49:19 |
版本与语言
安全公告
变更历史
查看详细变更
- vulnerability_type: 未提取 -> 授权问题
- cnnvd_id: 未提取 -> CNNVD-200708-128
- data_sources: ['cve', 'nvd'] -> ['cnnvd', 'cve', 'nvd']
查看详细变更
- severity: SeverityLevel.MEDIUM -> SeverityLevel.HIGH
- cvss_score: 未提取 -> 7.5
- cvss_vector: NOT_EXTRACTED -> AV:N/AC:L/Au:N/C:P/I:P/A:P
- cvss_version: NOT_EXTRACTED -> 2.0
- affected_products_count: 0 -> 1
- data_sources: ['cve'] -> ['cve', 'nvd']