{ "id": "CVE-2007-5278", "sourceIdentifier": "cve@mitre.org", "published": "2007-10-08T23:17:00.000", "lastModified": "2017-09-29T01:29:33.033", "vulnStatus": "Modified", "descriptions": [ { "lang": "en", "value": "Zomplog 3.8.1 and earlier stores potentially sensitive information under the web root with insufficient access control, which allows remote attackers to download files that were uploaded by users, as demonstrated by obtaining a directory listing via a direct request to /upload and then retrieving individual files. NOTE: in a non-default configuration, the directory listing is denied, but filenames may be predicable." }, { "lang": "es", "value": "Zomplog 3.8.1 y anteriores almacena informaci\u00f3n potencialmente sensible bajo la ra\u00edz web con control de acceso insuficiente, lo cual permite a atacantes remotos descargar archivos que han sido enviados por los usuarios, como se ha demostrado obteniendo un listado de directorio mediante una petici\u00f3n directa de /upload y despu\u00e9s recuperando archivos individuales. NOTA: en una configuraci\u00f3n no por defecto, el listado de directorio est\u00e1 denegado, pero los nombres de archivo pueden ser predecibles." } ], "metrics": { "cvssMetricV2": [ { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "2.0", "vectorString": "AV:N/AC:M/Au:N/C:P/I:N/A:N", "accessVector": "NETWORK", "accessComplexity": "MEDIUM", "authentication": "NONE", "confidentialityImpact": "PARTIAL", "integrityImpact": "NONE", "availabilityImpact": "NONE", "baseScore": 4.3 }, "baseSeverity": "MEDIUM", "exploitabilityScore": 8.6, "impactScore": 2.9, "acInsufInfo": false, "obtainAllPrivilege": false, "obtainUserPrivilege": false, "obtainOtherPrivilege": false, "userInteractionRequired": false } ] }, "weaknesses": [ { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-264" } ] } ], "configurations": [ { "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:zomplog:zomplog:3.8.1:*:*:*:*:*:*:*", "matchCriteriaId": "376C40ED-9457-4A91-8616-FE6ABABFF187" } ] } ] } ], "references": [ { "url": "http://www.securityfocus.com/bid/25861", "source": "cve@mitre.org", "tags": [ "Exploit", "Patch" ] }, { "url": "https://www.exploit-db.com/exploits/4466", "source": "cve@mitre.org" } ] }