6.8
CVSSv2

CVE-2008-5919

Published: 21/01/2009 Updated: 29/09/2017
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
VMScore: 685
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

Directory traversal vulnerability in rss.php in WebSVN 2.0 and previous versions, when magic_quotes_gpc is disabled, allows remote malicious users to overwrite arbitrary files via directory traversal sequences in the rev parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

tigris websvn 1.61

tigris websvn 1.62

tigris websvn 1.51

tigris websvn 1.32

tigris websvn 1.31a

tigris websvn 1.00

tigris websvn 1.40

tigris websvn 1.39

tigris websvn 1.20

tigris websvn 1.10

tigris websvn 1.38

tigris websvn 1.37

tigris websvn 1.04

tigris websvn 1.03

tigris websvn

tigris websvn 1.60

tigris websvn 1.34

tigris websvn 1.33

tigris websvn 1.02

tigris websvn 1.01

Exploits

WebSVN <= 20 Multiple Vulnerabilities October 20, 2008 Vendor : Tim Armes URL : websvntigrisorg Version : WebSVN <= 20 Risk : Multiple Vulnerabilities Description: WebSVN is an online SVN repository viewer The description taken from the project website reads "WebSVN offers a view onto your subversion repositories that's b ...