Lucene search

K
cve[email protected]CVE-2008-5856
HistoryJan 06, 2009 - 5:30 p.m.

CVE-2008-5856

2009-01-0617:30:00
CWE-22
web.nvd.nist.gov
22
directory traversal
vulnerability
class
scripts
export.php
ftype parameter
remote attackers
arbitrary files

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.9 Medium

AI Score

Confidence

Low

0.019 Low

EPSS

Percentile

88.5%

Directory traversal vulnerability in scripts/export.php in ClaSS before 0.8.61 allows remote attackers to read arbitrary files via directory traversal sequences in the ftype parameter.

Affected configurations

NVD
Node
classclassRange0.8.60
OR
classclassMatch0.4beta
OR
classclassMatch0.4.0
OR
classclassMatch0.4.1
OR
classclassMatch0.4.2
OR
classclassMatch0.5.0
OR
classclassMatch0.5.1
OR
classclassMatch0.5.2
OR
classclassMatch0.6.0
OR
classclassMatch0.6.1
OR
classclassMatch0.8rc2
OR
classclassMatch0.8.0
OR
classclassMatch0.8.0rc1
OR
classclassMatch0.8.5
OR
classclassMatch0.8.8
OR
classclassMatch0.8.10
OR
classclassMatch0.8.14
OR
classclassMatch0.8.20
OR
classclassMatch0.8.26
OR
classclassMatch0.8.29
OR
classclassMatch0.8.32
OR
classclassMatch0.8.40
OR
classclassMatch0.8.47
OR
classclassMatch0.8.51
OR
classclassMatch0.8.56
OR
classclassMatch0.8.59

5 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

6.9 Medium

AI Score

Confidence

Low

0.019 Low

EPSS

Percentile

88.5%

Related for CVE-2008-5856