Lucene search

K
cveMitreCVE-2008-3371
HistoryJul 30, 2008 - 5:41 p.m.

CVE-2008-3371

2008-07-3017:41:00
CWE-22
mitre
web.nvd.nist.gov
19
cve-2008-3371
directory traversal
talkback
vulnerability
remote attackers
local files
language parameter

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

High

EPSS

0.025

Percentile

90.2%

Directory traversal vulnerability in install/help.php in TalkBack 2.3.5, and other versions before 2.3.6.2, allows remote attackers to include and execute arbitrary local files via directory traversal sequences in the language parameter.

Affected configurations

Nvd
Node
talkbacktalkbackMatch2.3.5
VendorProductVersionCPE
talkbacktalkback2.3.5cpe:2.3:a:talkback:talkback:2.3.5:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

7.2

Confidence

High

EPSS

0.025

Percentile

90.2%

Related for CVE-2008-3371