CVE-2007-2197
Summary
| CVE | CVE-2007-2197 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-04-24 17:19:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Race condition in the NeatUpload ASP.NET component 1.2.11 through 1.2.16, 1.1.18 through 1.1.23, and trunk.379 through trunk.445 allows remote attackers to obtain other clients' HTTP responses via multiple simultaneous requests, which triggers multiple calls to HttpWorkerRequest.FlushResponse for the same HttpWorkerRequest object and causes a buffer to be reused for a different request. |
Risk And Classification
Primary CVSS: v2.0 5 from [email protected]
AV:N/AC:L/Au:N/C:P/I:N/A:N
Problem Types: NVD-CWE-Other | n/a
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:N/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Brettle Development | Neatupload | 1.1.18 | All | All | All |
| Application | Brettle Development | Neatupload | 1.1.19 | All | All | All |
| Application | Brettle Development | Neatupload | 1.1.20 | All | All | All |
| Application | Brettle Development | Neatupload | 1.1.21 | All | All | All |
| Application | Brettle Development | Neatupload | 1.1.22 | All | All | All |
| Application | Brettle Development | Neatupload | 1.1.23 | All | All | All |
| Application | Brettle Development | Neatupload | 1.2.11 | All | All | All |
| Application | Brettle Development | Neatupload | 1.2.12 | All | All | All |
| Application | Brettle Development | Neatupload | 1.2.13 | All | All | All |
| Application | Brettle Development | Neatupload | 1.2.14 | All | All | All |
| Application | Brettle Development | Neatupload | 1.2.15 | All | All | All |
| Application | Brettle Development | Neatupload | 1.2.16 | All | All | All |
| Application | Brettle Development | Neatupload | trunk.379 | All | All | All |
| Application | Brettle Development | Neatupload | trunk.380 | All | All | All |
| Application | Brettle Development | Neatupload | trunk.381 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| NeatUpload Response Handling Race Condition Information Disclosure - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Vendor Advisory |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| NeatUpload HTTPWorkerRequest.FlushResponse Information Disclosure Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| SecurityFocus | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.