5
CVSSv2

CVE-2007-2747

Published: 17/05/2007 Updated: 29/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in rdw_helpers.py in rdiffWeb prior to 0.3.5.1 allows remote malicious users to read arbitrary files via a .. (dot dot) in the path parameter to the /browse URI.

Vulnerable Product Search on Vulmon Subscribe to Product

rdiffweb rdiffweb

rdiffweb rdiffweb 0.1

rdiffweb rdiffweb 0.3.1

rdiffweb rdiffweb 0.3.2

rdiffweb rdiffweb 0.2

rdiffweb rdiffweb 0.3

Exploits

source: wwwsecurityfocuscom/bid/24092/info rdiffWeb is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input An attacker can exploit this vulnerability to retrieve arbitrary files from the vulnerable system in the context of the webserver process Information obtained may aid in further a ...