|
| Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl) | | Published: |  | 25.01.2008 | | Source: |  | | | SecurityVulns ID: |  | 8607 | | Type: |  | remote | | Level: |  | 5/10 | | Description: |  | PHP inclusions, SQL injections, directory traversals, crossite scripting, information leaks, etc.
Relay: SQL injection and crossite scripting. |
| Affected: |  | PHPBB : phpBB 2.0 | | |  | CHERRYPY : CherryPy 3.0 | | |  | CANDYPRESS : CandyPress 4.1 | | CVE: |  | CVE-2008-0252 (Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py in CherryPy 2.1, and (3) filter/sessionfilter.py in CherryPy 2.x allows remote attackers to create or delete arbitrary files, and possibly read and write portions of arbitrary files, via a crafted session id in a cookie.) |
|
|
|
|
|