4
CVSSv2

CVE-2008-5678

Published: 19/12/2008 Updated: 29/09/2017
CVSS v2 Base Score: 4 | Impact Score: 2.9 | Exploitability Score: 8
VMScore: 405
Vector: AV:N/AC:L/Au:S/C:P/I:N/A:N

Vulnerability Summary

Fretwell-Downing Informatics (FDI) OLIB7 WebView 2.5.1.1 allows remote authenticated users to obtain sensitive information from files via the infile parameter to the default URI under cgi/, as demonstrated by the (1) get_settings.ini, (2) setup.ini, and (3) text.ini files.

Vulnerable Product Search on Vulmon Subscribe to Product

fdgroup olib7 webview 2.5.1.1

Exploits

Security Advisory for 'OLIB 7 Webview' This software is apart of Moodle Software - OLIB 7 WebView v2511 Exploit - LFI Severity - High Author - ZeN website - dusecuritycom/ Date - 2nd October 2008 DUSecurity Team / DarkCode Exploit > olibsitecom/cgi/?session=[session_key]&infile=[LFI] files in dir - get_setting ...