René Helmke 7791f18b51 bootstrap
2023-05-16 16:09:41 +02:00

90 lines
2.8 KiB
JSON

{
"id": "CVE-2008-6522",
"sourceIdentifier": "cve@mitre.org",
"published": "2009-03-25T18:30:00.327",
"lastModified": "2018-10-11T20:57:22.560",
"vulnStatus": "Modified",
"descriptions": [
{
"lang": "en",
"value": "Multiple directory traversal vulnerabilities in the RenderFile function in ContentRender.class.php in Terracotta (aka OpenTerracotta) 0.6.1, and possibly other versions, allow remote attackers to list arbitrary directories and read arbitrary files via a .. (dot dot) in the (1) CurrentDirectory and (2) File parameters to index.php."
},
{
"lang": "es",
"value": "M\u00faltiples vulnerabilidades de salto de directorio en la funci\u00f3n RenderFile function in ContentRender.class.php en Terracotta (tambi\u00e9n conocida como OpenTerracotta) v0.6.1, y posiblemente otras versiones, permite a atacantes remotos listar directorios de su elecci\u00f3n y leer archivos a trav\u00e9s de .. (punto punto) en los par\u00e1metros (1) \"CurrentDirectory\" y (2) \"File\" al index.php."
}
],
"metrics": {
"cvssMetricV2": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"cvssData": {
"version": "2.0",
"vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
"accessVector": "NETWORK",
"accessComplexity": "MEDIUM",
"authentication": "NONE",
"confidentialityImpact": "PARTIAL",
"integrityImpact": "PARTIAL",
"availabilityImpact": "PARTIAL",
"baseScore": 6.8
},
"baseSeverity": "MEDIUM",
"exploitabilityScore": 8.6,
"impactScore": 6.4,
"acInsufInfo": false,
"obtainAllPrivilege": false,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"weaknesses": [
{
"source": "nvd@nist.gov",
"type": "Primary",
"description": [
{
"lang": "en",
"value": "CWE-22"
}
]
}
],
"configurations": [
{
"nodes": [
{
"operator": "OR",
"negate": false,
"cpeMatch": [
{
"vulnerable": true,
"criteria": "cpe:2.3:a:devraj_mukherjee:openterracotta:0.6.1:*:*:*:*:*:*:*",
"matchCriteriaId": "028C0FC4-29C8-46C2-8F27-EA8E08734E20"
}
]
}
]
}
],
"references": [
{
"url": "http://www.securityfocus.com/archive/1/490341/100/0/threaded",
"source": "cve@mitre.org"
},
{
"url": "http://www.securityfocus.com/bid/28550",
"source": "cve@mitre.org",
"tags": [
"Exploit"
]
},
{
"url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/41572",
"source": "cve@mitre.org"
}
]
}