CVE-2007-5119: Input Validation
Published Sep 27, 2007
·Updated
JSPWiki 2.4.103 and 2.5.139-beta allows remote attackers to obtain sensitive information (full path) via an invalid integer in the version parameter to the default URI under attach/Main/.
Affected Software
2 affected components
JSPWiki JSPWiki=2.4.103
JSPWiki JSPWiki=2.5.139-beta
Remediation
Patch Available
Event History
Sep 27, 2007
CVE Published
via MITRE·05:00 PM
Data Sourced
via MITRE·05:00 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2007-5119?
CVE-2007-5119 has a low severity rating as it allows access to sensitive information rather than executing arbitrary code.
2
How do I fix CVE-2007-5119?
To fix CVE-2007-5119, upgrade to JSPWiki version 2.4.104 or later, or to 2.5.140-beta to mitigate the vulnerability.
3
What types of information can be exposed by CVE-2007-5119?
CVE-2007-5119 can expose the full file path of the application server and potentially sensitive information shortcuts.
4
Which versions of JSPWiki are affected by CVE-2007-5119?
CVE-2007-5119 affects JSPWiki versions 2.4.103 and 2.5.139-beta.
5
Is CVE-2007-5119 a common vulnerability in web applications?
CVE-2007-5119 represents a common vulnerability known as information disclosure, which is often exploited to gather further attack vectors.