CVE-2010-1326 is a critical vulnerability affecting March Hare Software CVSNT and CVS Suite versions, allowing remote attackers to bypass permission checks. By crafting a malicious branch name ACL, attackers can modify arbitrary modules and directories within CVSROOT, potentially leading to arbitrary code execution. With a CVSS score of 9.3, this vulnerability has a high severity due to its network-based attack vector, medium attack complexity, and complete compromise of confidentiality, integrity, and availability. There is no evidence of active exploitation, publicly available exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2.5.03CPE matchmatch criteria | cpe:2.3:a:march-hare:cvs_suite:2.5.03:*:*:*:*:*:*:* | ||
2008CPE matchmatch criteria | cpe:2.3:a:march-hare:cvs_suite:2008:*:*:*:*:*:*:* | ||
2009CPE matchmatch criteria | cpe:2.3:a:march-hare:cvs_suite:2009:pre-release:*:*:*:*:*:* | ||
2.0.58CPE matchmatch criteria | cpe:2.3:a:march-hare:cvsnt:2.0.58:*:*:*:*:*:*:* | ||
2.5.01CPE matchmatch criteria | cpe:2.3:a:march-hare:cvsnt:2.5.01:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.