Lucene search

K
cve[email protected]CVE-2008-0466
HistoryJan 29, 2008 - 12:00 a.m.

CVE-2008-0466

2008-01-2900:00:00
CWE-287
web.nvd.nist.gov
25
cve
2008
web wiz
rte
file browser
authentication
remote attackers
directory traversal
nvd

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.6 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.1%

Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a separate directory traversal vulnerability.

Affected configurations

NVD
Node
webwizweb_wiz_forumsMatch9.07
Node
webwizweb_wiz_newspadMatch1.02
Node
webwizweb_wiz_rich_text_editorMatch4.0

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.6 Medium

AI Score

Confidence

Low

0.005 Low

EPSS

Percentile

77.1%

Related for CVE-2008-0466