Lucene search

K
cveMitreCVE-2007-0337
HistoryJan 18, 2007 - 2:28 a.m.

CVE-2007-0337

2007-01-1802:28:00
mitre
web.nvd.nist.gov
38
cve
2007
directory traversal
vulnerability
kgb 1.9
remote attackers
arbitrary file execution

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.054

Percentile

93.2%

Directory traversal vulnerability in sesskglogadmin.php in KGB 1.9 and earlier allows remote attackers to include and execute arbitrary local files via a … (dot dot) in the skinnn parameter, as demonstrated by invoking kg.php with a postek parameter containing PHP code, which is injected into a file in the kg directory, and then included by sesskglogadmin.php.

Affected configurations

Nvd
Node
kgbkgbRange1.9
VendorProductVersionCPE
kgbkgb*cpe:2.3:a:kgb:kgb:*:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

Low

EPSS

0.054

Percentile

93.2%