First published: Mon Sep 17 2007(Updated: )
Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pilih parameter.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Tina Tinacms | =1.5_rc | |
Tina Tinacms | =1.5 | |
Tina Tinacms | =1.0 | |
Tina Tinacms | =2.0 | |
Tina Tinacms | =2.1 | |
Tina Tinacms | =1.62 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-4908 has a medium severity level due to its potential for arbitrary file inclusion.
To fix CVE-2007-4908, update AuraCMS to version 2.2 or later, which addresses this vulnerability.
CVE-2007-4908 affects AuraCMS versions 1.0, 1.5, 1.5_rc, 2.0, and 2.1.
CVE-2007-4908 is a directory traversal vulnerability that allows remote attackers to execute arbitrary local files.
Yes, CVE-2007-4908 can be exploited remotely through specially crafted requests.