CVE-2013-6496
published 2014-10-06CVE-2013-6496: Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4)…
PriorityP425medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
1.78%
75.8th percentile
Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4) portal_skins/custom, or (5) logs Luci extension.
Affected
1 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | conga | — | — |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
conga: Multiple information leak flaws in various luci site extensions
vendor_redhat·2014-09-16·CVSS 5.0
CVE-2013-6496 [MEDIUM] CWE-306 conga: Multiple information leak flaws in various luci site extensions
conga: Multiple information leak flaws in various luci site extensions
Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4) portal_skins/custom, or (5) logs Luci extension.
Multiple information leak flaws were found in the way conga processed luci site extension-related URL requests. A remote, unauthenticated attacker could issue a specially crafted HTTP request that, when processed, would result in unauthorized information disclosure.
Package: conga (Red Hat Enterprise Linux 5) - Affected
Package: luci (Red Hat Enterprise Linux 6) - Not affected
GHSA
GHSA-qg9g-f276-3vp4: Red Hat Conga 0
ghsa_unreviewed·2022-05-17
CVE-2013-6496 [MEDIUM] CWE-200 GHSA-qg9g-f276-3vp4: Red Hat Conga 0
Red Hat Conga 0.12.2 allows remote attackers to obtain sensitive information via a crafted request to the (1) homebase, (2) cluster, (3) storage, (4) portal_skins/custom, or (5) logs Luci extension.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6496 conga: Multiple information leak flaws in various luci site extensions
bugzilla·2013-06-06·CVSS 5.0
CVE-2013-6496 [MEDIUM] CVE-2013-6496 conga: Multiple information leak flaws in various luci site extensions
CVE-2013-6496 conga: Multiple information leak flaws in various luci site extensions
Multiple information leak flaws were found in the way conga, a remote management system, processed Luci site extensions related URL requests, involving the following components:
* homebase
* cluster
* storage
* portal_skins/custom
* logs
A remote attacker could issue a specially-crafted HTTP request against conga that, when processed would lead to unauthorized information disclosure (in various Luci site extension components).
This issue was discovered by Jan Pokorny of Red Hat.
Discussion:
This issue affects the version of the conga package, as shipped with Red Hat Enterprise Linux 5.
--
This issue did NOT affect the version of the luci package, as shipped with Red Hat Enterprise Linux 6.
---
Ac
Bugzilla
CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls
bugzilla·2013-01-04·CVSS 7.5
CVE-2012-6497 [HIGH] CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls
CVE-2012-6497 rubygem-authlogic: potential unsafe find_by_id method calls
Common Vulnerabilities and Exposures assigned an identifier CVE-2012-6497 to
the following vulnerability:
Name: CVE-2012-6497
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2012-6497
Assigned: 20130103
Reference: http://openwall.com/lists/oss-security/2013/01/03/12
Reference: http://blog.phusion.nl/2013/01/03/rails-sql-injection-vulnerability-hold-your-horses-here-are-the-facts/
Reference: http://phenoelit.org/blog/archives/2012/12/21/let_me_github_that_for_you/index.html
The Authlogic gem for Ruby on Rails, when used with certain versions
before 3.2.10, makes potentially unsafe find_by_id method calls, which
might allow remote attackers to conduct CVE-2012-6496 SQL injection
attacks via a crafted paramete
2014-10-06
Published