9.3
CVSSv2

CVE-2008-1231

Published: 10/03/2008 Updated: 29/09/2017
CVSS v2 Base Score: 9.3 | Impact Score: 10 | Exploitability Score: 8.6
VMScore: 935
Vector: AV:N/AC:M/Au:N/C:C/I:C/A:C

Vulnerability Summary

Directory traversal vulnerability in Edit.jsp in JSPWiki 2.4.104 and 2.5.139 allows remote malicious users to include and execute arbitrary local .jsp files, and obtain sensitive information, via a .. (dot dot) in the editor parameter.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

jspwiki jspwiki 2.5.139_beta

jspwiki jspwiki 2.4.104

jspwiki jspwiki 2.5.139

Exploits

JSPWiki Multiple Vulnerabilities Vendor: Janne Jalkanen JSPWiki – wwwjspwikiorg Application Description: From JSPWiki website - “JSPWiki is a feature-rich and extensible WikiWiki engine built around a standart J2EE components (Java, servlets, JSP)” Tested versions: JSPWiki v24104 JSPWiki v25139 Earlier versions ...