PT-2007-6726 · Battle For Wesnoth · Wesnoth
Publicado
2007-12-01
·
Atualizado
2017-07-29
·
CVE-2007-5742
CVSS v2.0
9.0
Alta
| Vetor | AV:N/AC:L/Au:N/C:P/I:P/A:C |
Name of the Vulnerable Software and Affected Versions
Wesnoth versions 1.2.x through 1.2.7
Wesnoth versions 1.3.x through 1.3.11
Description
A directory traversal issue exists in the WML engine preprocessor, allowing remote attackers to read arbitrary files by using ".." sequences in unknown vectors.
Recommendations
For Wesnoth versions 1.2.x through 1.2.7, update to version 1.2.8 or later.
For Wesnoth versions 1.3.x through 1.3.11, update to version 1.3.12 or later.
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wesnoth