CVE-2007-1158: Medium severity Postnuke Software Foundation Pagesetter vulnerability
Published Feb 28, 2007
·Updated
Directory traversal vulnerability in index.php in the Pagesetter 6.2.0 through 6.3.0 beta 5 module for PostNuke allows remote attackers to read arbitrary files via a .. (dot dot) in the id parameter.
Affected Software
2 affected components
Postnuke Software Foundation Pagesetter=6.3.0-beta_5
Postnuke Software Foundation Pagesetter=6.2
Remediation
Patch Available
Event History
Feb 28, 2007
CVE Published
via MITRE·05:00 AM
Data Sourced
via MITRE·05:00 AM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-1158?
CVE-2007-1158 has a moderate severity level due to its ability to allow unauthorized access to sensitive files.
2
How do I fix CVE-2007-1158?
To fix CVE-2007-1158, upgrade Pagesetter to the latest version that addresses this vulnerability.
3
What systems are affected by CVE-2007-1158?
CVE-2007-1158 affects Pagesetter versions 6.2 and 6.3.0 beta 5 within the PostNuke platform.
4
What type of attack does CVE-2007-1158 facilitate?
CVE-2007-1158 facilitates directory traversal attacks, allowing remote attackers to read arbitrary files on the server.
5
Is CVE-2007-1158 easy to exploit?
Yes, CVE-2007-1158 is relatively easy to exploit, requiring only knowledge of the vulnerable parameter.