ALERT CVE-2008-3195
Description : Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files via a query string containing a .. (dot dot) in the image variable, and execute arbitrary files via unspecified vectors. Read more ...
VECTOR BRIEF
| FULL CVSS v2 VECTOR | |
| (AV:N/AC:M/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:ND/CDP:ND/TD:ND/CR:ND/IR:ND/AR:ND) | |
| BASE METRICS | |
Access Vector : Network * Access Complexity : Medium * Authentification : None Required * |
Confidentiality : Partial * Integrity : Partial * Availability : Partial * |
| * Required | |
| ENVIRONMENTAL METRICS | |
Confidentiality Requirement : Not Defined Integrity Requirement : Not Defined Availability Requirement : Not Defined |
Collateral Damage Potential : Not Defined Target Distribution : Not Defined |
| TEMPORAL METRICS | |
Exploitability : Not Defined Remediation Level : Not Defined Report Confidence : Not Defined |
|
Security Dashboard



CVSS Base Score : 6.8

