5
CVSSv2

CVE-2007-6651

Published: 04/01/2008 Updated: 15/10/2018
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in wiki/edit.php in Bitweaver R2 CMS allows remote malicious users to obtain sensitive information (script source code) via a .. (dot dot) in the suck_url parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

bitweaver bitweaver 2.0.0

Exploits

########################## WwWBugReportir ######################### # # AmnPardaz Security Research Team # # Title: Bitweaver R2 CMS # Vendor: wwwbitweaverorg # Bugs: source code disclosure, arbitrary file upload # Vulnerable Version: 2 (prior versions also may be affected) # Exploitation: Remote with browser # Fix Available: No! ## ...