First published: Wed Feb 28 2007(Updated: )
Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Postnuke Software Foundation Pagesetter | =6.3.0-beta_5 | |
Postnuke Software Foundation Pagesetter | =6.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-1158 has a moderate severity level due to its ability to allow unauthorized access to sensitive files.
To fix CVE-2007-1158, upgrade Pagesetter to the latest version that addresses this vulnerability.
CVE-2007-1158 affects Pagesetter versions 6.2 and 6.3.0 beta 5 within the PostNuke platform.
CVE-2007-1158 facilitates directory traversal attacks, allowing remote attackers to read arbitrary files on the server.
Yes, CVE-2007-1158 is relatively easy to exploit, requiring only knowledge of the vulnerable parameter.