CVE-2007-2590
Title: Nokia Intellisync Mobile Suite Information Disclosure
Information Disclosure
Proof Of Concept
No public PoC currently indexed for CVE-2007-2590.
CWE Category
CWE-200
Published Date
May 11, 2007
Modified Date
Apr 09, 2025
Exploit Status
Not Found
Score
6.4
CVSS v2.0
Exploit Probability (EPSS)
0.76%
Vulnerability Summary
CVE-2007-2590: Nokia Intellisync Mobile Suite 6.4.31.2, 6.6.0.107, and 6.6.2.2, possibly involving Novell Groupwise Mobile Server and Nokia Intellisync Wireless Email Express, allows remote attackers to obtain user names and other sensitive information via a direct request to (1) usrmgr/userList.asp or (2) usrmgr/userStatusList.asp.
Impacted Vendors
Reference Links
http://osvdb.org/34514
http://secunia.com/advisories/25212
http://securityreason.com/securityalert/2689
http://www.sec-consult.com/289.html
http://www.securityfocus.com/archive/1/468048/100/0/threaded
http://www.vupen.com/english/advisories/2007/1727
http://osvdb.org/34514
http://secunia.com/advisories/25212
http://securityreason.com/securityalert/2689
http://www.sec-consult.com/289.html
http://www.securityfocus.com/archive/1/468048/100/0/threaded
http://www.vupen.com/english/advisories/2007/1727
CVSS v2.0
Source Entity
[email protected]
Severity
MEDIUM
6.4
Access Vector
N/A
Authentication
N/A
RAW VECTOR
AV:N/AC:L/Au:N/C:P/I:P/A:N
Associated Attack Patterns (CAPEC)
Total: PatternsNo specific attack patterns mapped.
Likelihood
Severity
Page /
CVE-2007-2590 Exploits & PoCs (Proof Of Concept)
No public PoCs found in our database for this CVE.
MODIFIED
Vulnerability data or affected products updated.
PUBLISHED
Vulnerability first announced in NVD.
Attack Vector Matrix
Access Vector
N/A
Complexity
N/A
Privileges
N/A
Interaction
NONE
CVSS Vector String
AV:N/AC:L/Au:N/C:P/I:P/A:N
Affected Stack
No specific products linked.