Lucene search

K
cveMitreCVE-2007-6662
HistoryJan 04, 2008 - 11:46 a.m.

CVE-2007-6662

2008-01-0411:46:00
CWE-22
mitre
web.nvd.nist.gov
25
cutenews
2.6
directory traversal
vulnerability
file.php
remote attackers
arbitrary files
admin username
password hash
nvd

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.9

Confidence

Low

EPSS

0.003

Percentile

68.2%

Directory traversal vulnerability in file.php in CuteNews 2.6 allows remote attackers to read arbitrary files via a … (dot dot) in the file parameter, as demonstrated by reading the admin username and password hash in data/users.db.php.

Affected configurations

Nvd
Node
cutephpcutenewsMatch2.6
VendorProductVersionCPE
cutephpcutenews2.6cpe:2.3:a:cutephp:cutenews:2.6:*:*:*:*:*:*:*

CVSS2

5.8

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:P/A:N

AI Score

6.9

Confidence

Low

EPSS

0.003

Percentile

68.2%

Related for CVE-2007-6662