[Forgot Password]
Login  Register Subscribe

24128

 
 

131615

 
 

112965

 
 

909

 
 

87888

 
 

136

Paid content will be excluded from the download.


Download | Alert*
CVE
view XML view JSON

CVE-2007-2836Date: (C)2007-07-02   (M)2018-02-19


Directory traversal vulnerability in session.rb in Hiki 0.8.0 through 0.8.6 allows remote attackers to delete arbitrary files via directory traversal sequences in the session ID, which is matched against an insufficiently restrictive regular expression before it is used to construct a filename that is marked for deletion at logout.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 6.4
Exploit Score: 10.0
Impact Score: 4.9
 
CVSS V2 Metrics:
Access Vector: NETWORK
Access Complexity: LOW
Authentication: NONE
Confidentiality: NONE
Integrity: PARTIAL
Availability: PARTIAL
  
Reference:
BID-24603
SECUNIA-25764
SECUNIA-25874
OSVDB-37469
ADV-2007-2304
DSA-1324
JVN#05187780
hiki-sessionid-security-bypass(35029)
http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=430691
http://hikiwiki.org/en/advisory20070624.html
http://hikiwiki.org/hiki-0_8_6.patch

CWE    1
CWE-22

© SecPod Technologies