{"api_version":"1","generated_at":"2026-07-23T05:43:28+00:00","cve":"CVE-2010-2271","urls":{"html":"https://cve.report/CVE-2010-2271","api":"https://cve.report/api/cve/CVE-2010-2271.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2010-2271","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2010-2271"},"summary":{"title":"CVE-2010-2271","description":"Format string vulnerability in authcfg.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to have an unspecified impact via format string specifiers in the path (aka Password File) parameter.","state":"PUBLISHED","assigner":"mitre","published_at":"2010-06-15 14:30:01","updated_at":"2026-04-29 01:13:23"},"problem_types":["CWE-134","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:P/A:P","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"}}],"references":[{"url":"http://www.ioactive.com/pdfs/AccoriaWebServer.pdf","name":"http://www.ioactive.com/pdfs/AccoriaWebServer.pdf","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Page not found | IOActive","mime":"text/html","httpstatus":"404","archivestatus":"404"},{"url":"http://www.kb.cert.org/vuls/id/245081","name":"http://www.kb.cert.org/vuls/id/245081","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["US Government Resource"],"title":"US-CERT Vulnerability Note VU#245081","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2010-2271","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2010-2271","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2010","cve_id":"2271","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"accoria","cpe5":"rock_web_server","cpe6":"1.4.7","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T02:25:07.581Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.ioactive.com/pdfs/AccoriaWebServer.pdf"},{"name":"VU#245081","tags":["third-party-advisory","x_refsource_CERT-VN","x_transferred"],"url":"http://www.kb.cert.org/vuls/id/245081"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"descriptions":[{"lang":"en","value":"Format string vulnerability in authcfg.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to have an unspecified impact via format string specifiers in the path (aka Password File) parameter."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2010-06-14T19:00:00.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.ioactive.com/pdfs/AccoriaWebServer.pdf"},{"name":"VU#245081","tags":["third-party-advisory","x_refsource_CERT-VN"],"url":"http://www.kb.cert.org/vuls/id/245081"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2010-2271","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Format string vulnerability in authcfg.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to have an unspecified impact via format string specifiers in the path (aka Password File) parameter."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.ioactive.com/pdfs/AccoriaWebServer.pdf","refsource":"MISC","url":"http://www.ioactive.com/pdfs/AccoriaWebServer.pdf"},{"name":"VU#245081","refsource":"CERT-VN","url":"http://www.kb.cert.org/vuls/id/245081"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2010-2271","datePublished":"2010-06-14T19:00:00.000Z","dateReserved":"2010-06-14T00:00:00.000Z","dateUpdated":"2024-09-16T17:08:55.138Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2010-06-15 14:30:01","lastModifiedDate":"2026-04-29 01:13:23","problem_types":["CWE-134","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:P/A:P","baseScore":7.5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"PARTIAL","availabilityImpact":"PARTIAL"},"baseSeverity":"HIGH","exploitabilityScore":10,"impactScore":6.4,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:accoria:rock_web_server:1.4.7:*:*:*:*:*:*:*","matchCriteriaId":"D07F604B-CCDD-4F78-93FA-C63273EAD480"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2010","CveId":"2271","Ordinal":"1","Title":"CVE-2010-2271","CVE":"CVE-2010-2271","Year":"2010"},"notes":[{"CveYear":"2010","CveId":"2271","Ordinal":"1","NoteData":"Format string vulnerability in authcfg.cgi in Accoria Web Server (aka Rock Web Server) 1.4.7 allows remote attackers to have an unspecified impact via format string specifiers in the path (aka Password File) parameter.","Type":"Description","Title":"CVE-2010-2271"},{"CveYear":"2010","CveId":"2271","Ordinal":"2","NoteData":"2010-06-14","Type":"Other","Title":"Published"}]}}}