{"api_version":"1","generated_at":"2026-07-23T07:49:25+00:00","cve":"CVE-2007-1178","urls":{"html":"https://cve.report/CVE-2007-1178","api":"https://cve.report/api/cve/CVE-2007-1178.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-1178","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-1178"},"summary":{"title":"CVE-2007-1178","description":"WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration, and (3) the Image Uploader, which has unknown impact and attack vectors.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-03-02 21:18:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["NVD-CWE-Other","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://osvdb.org/33279","name":"http://osvdb.org/33279","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://secunia.com/advisories/24080","name":"http://secunia.com/advisories/24080","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"web-app.org WebAPP Multiple Vulnerabilities - Advisories - Secunia","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.vupen.com/english/advisories/2007/0604","name":"http://www.vupen.com/english/advisories/2007/0604","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webmail : Solution de messagerie professionnelle - OVHcloud- OVH","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/22563","name":"http://www.securityfocus.com/bid/22563","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Webapp.Org Webapp Multiple Remote Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=250","name":"http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=250","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Patch","Vendor Advisory"],"title":"Web-APP.org Articles : Announcements : WebAPP version 0.9.9.5 Early Release - WebAPP Web Automated Perl Portal","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/33282","name":"http://osvdb.org/33282","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-1178","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-1178","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"1178","vulnerable":"1","versionEndIncluding":"0.9.9.4","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"web-app.org","cpe5":"webapp","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T12:43:22.569Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=250"},{"name":"ADV-2007-0604","tags":["vdb-entry","x_refsource_VUPEN","x_transferred"],"url":"http://www.vupen.com/english/advisories/2007/0604"},{"name":"33282","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/33282"},{"name":"33279","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/33279"},{"name":"24080","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/24080"},{"name":"22563","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/22563"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-02-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration, and (3) the Image Uploader, which has unknown impact and attack vectors."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2008-11-15T10:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_CONFIRM"],"url":"http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=250"},{"name":"ADV-2007-0604","tags":["vdb-entry","x_refsource_VUPEN"],"url":"http://www.vupen.com/english/advisories/2007/0604"},{"name":"33282","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/33282"},{"name":"33279","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/33279"},{"name":"24080","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/24080"},{"name":"22563","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/22563"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-1178","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration, and (3) the Image Uploader, which has unknown impact and attack vectors."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=250","refsource":"CONFIRM","url":"http://www.web-app.org/cgi-bin/index.cgi?action=viewnews&id=250"},{"name":"ADV-2007-0604","refsource":"VUPEN","url":"http://www.vupen.com/english/advisories/2007/0604"},{"name":"33282","refsource":"OSVDB","url":"http://osvdb.org/33282"},{"name":"33279","refsource":"OSVDB","url":"http://osvdb.org/33279"},{"name":"24080","refsource":"SECUNIA","url":"http://secunia.com/advisories/24080"},{"name":"22563","refsource":"BID","url":"http://www.securityfocus.com/bid/22563"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-1178","datePublished":"2007-02-28T16:00:00.000Z","dateReserved":"2007-02-28T00:00:00.000Z","dateUpdated":"2024-08-07T12:43:22.569Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-03-02 21:18:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["NVD-CWE-Other","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:web-app.org:webapp:*:*:*:*:*:*:*:*","versionEndIncluding":"0.9.9.4","matchCriteriaId":"4053C685-A96A-43B3-8D78-E185AD837B5D"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"1178","Ordinal":"1","Title":"CVE-2007-1178","CVE":"CVE-2007-1178","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"1178","Ordinal":"1","NoteData":"WebAPP before 0.9.9.5 does not check access in certain contexts related to (1) Calendar Administration, (2) Instant Messages Administration, and (3) the Image Uploader, which has unknown impact and attack vectors.","Type":"Description","Title":"CVE-2007-1178"},{"CveYear":"2007","CveId":"1178","Ordinal":"2","NoteData":"2007-02-28","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"1178","Ordinal":"3","NoteData":"2008-11-15","Type":"Other","Title":"Modified"}]}}}