2024-05-26 14:27:05 +02:00
### [CVE-2007-5119](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-5119)



### Description
JSPWiki 2.4.103 and 2.5.139-beta allows remote attackers to obtain sensitive information (full path) via an invalid integer in the version parameter to the default URI under attach/Main/.
### POC
#### Reference
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/066096.html
2024-06-09 00:33:16 +00:00
- http://lists.grok.org.uk/pipermail/full-disclosure/2007-September/066096.html
2024-05-26 14:27:05 +02:00
- http://securityreason.com/securityalert/3167
2024-06-09 00:33:16 +00:00
- http://securityreason.com/securityalert/3167
2024-05-26 14:27:05 +02:00
#### Github
No PoCs found on GitHub currently.