PT-2009-1394 · Websvn · Websvn
James Bercegay
·
Published
2009-01-21
·
Updated
2017-09-29
·
CVE-2008-5919
CVSS v2.0
6.8
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
WebSVN versions 2.0 and earlier
Description
A directory traversal issue exists in the rss.php file of WebSVN, allowing remote attackers to overwrite arbitrary files when magic quotes gpc is disabled. This is achieved through directory traversal sequences in the
rev parameter.Recommendations
For WebSVN versions 2.0 and earlier, consider disabling the rss.php file or restricting access to it until a fix is available. As a temporary workaround, enable magic quotes gpc to prevent directory traversal attacks.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Websvn