Lucene search

K
cveMitreCVE-2007-5491
HistoryOct 17, 2007 - 7:17 p.m.

CVE-2007-5491

2007-10-1719:17:00
CWE-22
mitre
web.nvd.nist.gov
33
cve
2007
5491
directory traversal
sitebar
translator.php
remote user
chmod
lang parameter

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

6

Confidence

Low

EPSS

0.006

Percentile

78.5%

Directory traversal vulnerability in the translation module (translator.php) in SiteBar 3.3.8 allows remote authenticated users to chmod arbitrary files to 0777 via “…” sequences in the lang parameter.

Affected configurations

Nvd
Node
sitebarsitebarMatch3.3.8
VendorProductVersionCPE
sitebarsitebar3.3.8cpe:2.3:a:sitebar:sitebar:3.3.8:*:*:*:*:*:*:*

CVSS2

9

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

COMPLETE

Integrity Impact

COMPLETE

Availability Impact

COMPLETE

AV:N/AC:L/Au:S/C:C/I:C/A:C

AI Score

6

Confidence

Low

EPSS

0.006

Percentile

78.5%