Lucene search

K
nvd[email protected]NVD:CVE-2007-4957
HistorySep 18, 2007 - 8:17 p.m.

CVE-2007-4957

2007-09-1820:17:00
CWE-22
web.nvd.nist.gov
1

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.009

Percentile

82.8%

Multiple directory traversal vulnerabilities in download.php in Chupix CMS 0.2.3 allow remote attackers to read or overwrite arbitrary files via a … (dot dot) in the (1) fichier or (2) repertoire parameter, or create arbitrary directories via a … (dot dot) in the (3) repertoire parameter.

Affected configurations

Nvd
Node
chupixchupix_cmsMatch0.2.3
VendorProductVersionCPE
chupixchupix_cms0.2.3cpe:2.3:a:chupix:chupix_cms:0.2.3:*:*:*:*:*:*:*

CVSS2

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

PARTIAL

AV:N/AC:L/Au:N/C:P/I:P/A:P

AI Score

6.9

Confidence

Low

EPSS

0.009

Percentile

82.8%

Related for NVD:CVE-2007-4957