PT-2009-1394 · Websvn · Websvn
James Bercegay
·
Publicado
2009-01-21
·
Atualizado
2017-09-29
·
CVE-2008-5919
CVSS v2.0
6.8
Média
| Vetor | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
WebSVN versions 2.0 and earlier
Description
A directory traversal issue exists in the rss.php file of WebSVN, allowing remote attackers to overwrite arbitrary files when magic quotes gpc is disabled. This is achieved through directory traversal sequences in the
rev parameter.Recommendations
For WebSVN versions 2.0 and earlier, consider disabling the rss.php file or restricting access to it until a fix is available. As a temporary workaround, enable magic quotes gpc to prevent directory traversal attacks.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Websvn