PT-2007-6518 · Wwwisis · Wwwisis
Joss
·
Published
2007-10-16
·
Updated
2018-10-15
·
CVE-2007-5484
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
WWWISIS version 7.1
Description:
A directory traversal issue exists, allowing local users to read arbitrary files by using a .. (dot dot) in the
IsisScript parameter to the iah endpoint.Recommendations:
For WWWISIS version 7.1, avoid using the
IsisScript parameter with untrusted input until a fix is available. As a temporary workaround, consider restricting access to the iah endpoint to minimize the risk of exploitation.Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wwwisis