usrmgr/userList.asp in Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to modify user account details and cause a denial of service (account deactivation) via the userid parameter in an update action.
References
Link | Resource |
---|---|
http://osvdb.org/34513 | |
http://secunia.com/advisories/25212 | Patch Vendor Advisory |
http://securityreason.com/securityalert/2689 | |
http://www.sec-consult.com/289.html | Exploit Vendor Advisory |
http://www.securityfocus.com/archive/1/468048/100/0/threaded | |
http://www.vupen.com/english/advisories/2007/1727 |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: mitre
Published: 2007-05-11T03:55:00
Updated: 2018-10-16T14:57:01
Reserved: 2007-05-10T00:00:00
Link: CVE-2007-2591
JSON object: View
NVD Information
Status : Modified
Published: 2007-05-11T04:20:00.000
Modified: 2018-10-16T16:44:40.727
Link: CVE-2007-2591
JSON object: View
Redhat Information
No data.
CWE