117 lines
3.7 KiB
JSON
Raw Normal View History

2023-04-24 12:24:31 +02:00
{
"id": "CVE-2007-6361",
"sourceIdentifier": "cve@mitre.org",
"published": "2007-12-15T01:46:00.000",
"lastModified": "2024-11-21T00:39:57.877",
2023-04-24 12:24:31 +02:00
"vulnStatus": "Modified",
"cveTags": [],
2023-04-24 12:24:31 +02:00
"descriptions": [
{
"lang": "en",
"value": "Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server."
},
{
"lang": "es",
"value": "Gekko 0.8.2 y versiones anteriores guarda informaci\u00f3n sensible en el directorio ra\u00edz de la web, posiblemente, con un control de acceso insuficiente, lo que podr\u00eda permitir que atacantes remotos lean ciertos ficheros bajo temp/, tal y como demuestra un fichero de log que guarda los t\u00edtulos de las entradas del blog. NOTA: el acceso a temp/ est\u00e1 bloqueado por .htaccess en la mayor\u00eda de aplicaciones que usan Apache HTTP Server."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:L/Au:N/C:N/I:P/A:N",
"baseScore": 5.0,
2023-04-24 12:24:31 +02:00
"accessVector": "NETWORK",
"accessComplexity": "LOW",
"authentication": "NONE",
"confidentialityImpact": "NONE",
"integrityImpact": "PARTIAL",
"availabilityImpact": "NONE"
2023-04-24 12:24:31 +02:00
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 10.0,
"impactScore": 2.9,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:gekkoware:gekko:*:*:*:*:*:*:*:*",
"versionEndIncluding": "0.8.2",
"matchCriteriaId": "9ACA0485-6FE1-4E7B-8641-A2E5444A9F87"
}
]
}
]
}
],
"references": [
{
"url": "http://osvdb.org/44151",
"source": "cve@mitre.org"
},
2023-04-24 12:24:31 +02:00
{
"url": "http://securityreason.com/securityalert/3451",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/484330/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/archive/1/484343/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/38735",
"source": "cve@mitre.org"
},
{
"url": "http://osvdb.org/44151",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://securityreason.com/securityalert/3451",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/484330/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.securityfocus.com/archive/1/484343/100/0/threaded",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/38735",
"source": "af854a3a-2127-422b-91ae-364da2661108"
2023-04-24 12:24:31 +02:00
}
]
}