Executive Summary
Informations | |||
---|---|---|---|
Name | CVE-2007-2836 | First vendor Publication | 2007-07-02 |
Vendor | Cve | Last vendor Modification | 2024-11-21 |
Security-Database Scoring CVSS v3
Cvss vector : N/A | |||
---|---|---|---|
Overall CVSS Score | NA | ||
Base Score | NA | Environmental Score | NA |
impact SubScore | NA | Temporal Score | NA |
Exploitabality Sub Score | NA | ||
Calculate full CVSS 3.0 Vectors scores |
Security-Database Scoring CVSS v2
Cvss vector : (AV:N/AC:L/Au:N/C:N/I:P/A:P) | |||
---|---|---|---|
Cvss Base Score | 6.4 | Attack Range | Network |
Cvss Impact Score | 4.9 | Attack Complexity | Low |
Cvss Expoit Score | 10 | Authentication | None Required |
Calculate full CVSS 2.0 Vectors scores |
Detail
Directory traversal vulnerability in session.rb in Hiki 0.8.0 through 0.8.6 allows remote attackers to delete arbitrary files via directory traversal sequences in the session ID, which is matched against an insufficiently restrictive regular expression before it is used to construct a filename that is marked for deletion at logout. |
Original Source
Url : http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-2836 |
CWE : Common Weakness Enumeration
% | Id | Name |
---|---|---|
100 % | CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') (CWE/SANS Top 25) |
OVAL Definitions
Definition Id: oval:org.mitre.oval:def:18796 | |||
Oval ID: | oval:org.mitre.oval:def:18796 | ||
Title: | DSA-1324-1 hiki | ||
Description: | Kazuhiro Nishiyama found a vulnerability in hiki, a Wiki engine written in Ruby, which could allow a remote attacker to delete arbitrary files which are writable to the Hiki user, via a specially crafted session parameter. | ||
Family: | unix | Class: | patch |
Reference(s): | DSA-1324-1 CVE-2007-2836 | Version: | 7 |
Platform(s): | Debian GNU/Linux 4.0 | Product(s): | hiki |
Definition Synopsis: | |||
CPE : Common Platform Enumeration
Type | Description | Count |
---|---|---|
Application | 7 |
Open Source Vulnerability Database (OSVDB)
Id | Description |
---|---|
37469 | Hiki Session ID Traversal Arbitrary File Deletion |
Nessus® Vulnerability Scanner
Date | Description |
---|---|
2007-07-01 | Name : The remote Debian host is missing a security-related update. File : debian_DSA-1324.nasl - Type : ACT_GATHER_INFO |
Sources (Detail)
Alert History
Date | Informations |
---|---|
2024-11-28 23:16:56 |
|
2024-11-28 12:12:26 |
|
2021-05-04 12:05:50 |
|
2021-04-22 01:06:22 |
|
2020-05-23 00:19:50 |
|
2017-07-29 12:02:16 |
|
2016-06-28 16:32:13 |
|
2016-04-26 16:10:24 |
|
2014-02-17 10:40:17 |
|
2013-05-11 10:26:40 |
|