CVE-2007-4908: Path Traversal
Published Sep 17, 2007
·Updated
Directory traversal vulnerability in index.php in AuraCMS 2.1 and earlier allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the pilih parameter.
Affected Software
6 affected components
AuraCMS AuraCMS=1.5_rc
AuraCMS AuraCMS=1.5
AuraCMS AuraCMS=1.0
AuraCMS AuraCMS=2.0
AuraCMS AuraCMS=2.1
AuraCMS AuraCMS=1.62
Event History
Sep 17, 2007
CVE Published
04:17 PM
CVE Published
via MITRE·08:00 PM
Data Sourced
via MITRE·08:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-4908?
CVE-2007-4908 has a medium severity level due to its potential for arbitrary file inclusion.
2
How do I fix CVE-2007-4908?
To fix CVE-2007-4908, update AuraCMS to version 2.2 or later, which addresses this vulnerability.
3
What systems are affected by CVE-2007-4908?
CVE-2007-4908 affects AuraCMS versions 1.0, 1.5, 1.5_rc, 2.0, and 2.1.
4
What type of vulnerability is CVE-2007-4908?
CVE-2007-4908 is a directory traversal vulnerability that allows remote attackers to execute arbitrary local files.
5
Can CVE-2007-4908 be exploited remotely?
Yes, CVE-2007-4908 can be exploited remotely through specially crafted requests.