PT-2008-6730 · Fretwell Downing Informatics · Olib7 Webview

Zen

·

Published

2008-12-18

·

Updated

2017-09-29

·

CVE-2008-5678

CVSS v2.0

4.0

Medium

VectorAV:N/AC:L/Au:S/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Fretwell-Downing Informatics (FDI) OLIB7 WebView version 2.5.1.1
Description The issue allows remote authenticated users to obtain sensitive information from files via the infile parameter to the default URI under cgi/. This is demonstrated by accessing the get settings.ini, setup.ini, and text.ini files.
Recommendations For Fretwell-Downing Informatics (FDI) OLIB7 WebView version 2.5.1.1, consider restricting access to the cgi/ directory or limiting the use of the infile parameter to prevent unauthorized access to sensitive files.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2008-5678

Affected Products

Olib7 Webview