• Tenable
  • CVEs
  • Settings
    Links
    Tenable.io Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Links
  • Tenable.io
  • Tenable Community & Support
  • Tenable University
  • Settings
  • Severity
  • Theme
  • Newest
  • Updated
  • Search
  • Newest
  • Updated
  • Search
  1. CVEs
  2. CVE-2013-0213
  1. CVEs

CVE-2013-0213

medium
  • Information
  • CPEs
  • Plugins

Description

The Samba Web Administration Tool (SWAT) in Samba 3.x before 3.5.21, 3.6.x before 3.6.12, and 4.x before 4.0.2 allows remote attackers to conduct clickjacking attacks via a (1) FRAME or (2) IFRAME element.

References

http://lists.opensuse.org/opensuse-security-announce/2013-02/msg00019.html

http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00042.html

http://lists.opensuse.org/opensuse-updates/2013-02/msg00029.html

http://lists.opensuse.org/opensuse-updates/2013-02/msg00033.html

http://rhn.redhat.com/errata/RHSA-2013-1310.html

http://rhn.redhat.com/errata/RHSA-2013-1542.html

http://rhn.redhat.com/errata/RHSA-2014-0305.html

http://www.debian.org/security/2013/dsa-2617

http://www.samba.org/samba/security/CVE-2013-0213

http://www.securityfocus.com/bid/57631

http://www.ubuntu.com/usn/USN-2922-1

https://h20566.www2.hpe.com/portal/site/hpsc/public/kb/docDisplay?docId=emr_na-c05115993

Details

Source: MITRE

Published: 2013-02-02

Updated: 2018-10-30

Type: CWE-20

Risk Information

CVSS v2

Base Score: 5.1

Vector: AV:N/AC:H/Au:N/C:P/I:P/A:P

Impact Score: 6.4

Exploitability Score: 4.9

Severity: MEDIUM

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2022 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance