The DAV component in Chandler Server (Cosmo) before 0.10.1 does not check resource creation permissions, which allows remote authenticated users to create arbitrary resources in another user's home collection.
History

No history.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published: 2007-12-15T02:00:00

Updated: 2024-08-07T16:02:36.772Z

Reserved: 2007-12-14T00:00:00

Link: CVE-2007-6383

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2007-12-15T02:46:00.000

Modified: 2011-03-08T03:02:35.987

Link: CVE-2007-6383

cve-icon Redhat

No data.