Lucene search

K
cve[email protected]CVE-2009-5067
HistoryOct 10, 2012 - 6:55 p.m.

CVE-2009-5067

2012-10-1018:55:01
CWE-22
web.nvd.nist.gov
22
cve-2009-5067
directory traversal
html2ps
remote attackers
arbitrary files
ssi directive
vulnerability
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.9 Medium

AI Score

Confidence

Low

0.01 Low

EPSS

Percentile

83.9%

Directory traversal vulnerability in html2ps before 1.0b6 allows remote attackers to read arbitrary files via a … (dot dot) in the “include file” SSI directive. NOTE: this issue only might be a vulnerability in limited scenarios, such as if html2ps is invoked by a web application, or if a user-assisted attacker provides filenames whose contents could cause a denial of service, such as certain devices.

Affected configurations

NVD
Node
html2ps_projecthtml2psRange1.0b5
OR
html2ps_projecthtml2psMatch1.0b1
OR
html2ps_projecthtml2psMatch1.0b2
OR
html2ps_projecthtml2psMatch1.0b3
OR
html2ps_projecthtml2psMatch1.0b4

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.9 Medium

AI Score

Confidence

Low

0.01 Low

EPSS

Percentile

83.9%