First published: Sat Nov 10 2007(Updated: )
Directory traversal vulnerability in OpenBase 10.0.5 and earlier allows remote authenticated users to create files with arbitrary contents via a .. (dot dot) in the first argument to the GlobalLog stored procedure. NOTE: this can be leveraged to execute arbitrary code using CVE-2007-5926.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
David Branco Openbase | <=10.0.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2007-5927 has a high severity rating due to its potential for remote code execution.
To fix CVE-2007-5927, upgrade OpenBase to version 10.0.6 or later to eliminate the directory traversal vulnerability.
Remote authenticated users of OpenBase version 10.0.5 and earlier are affected by CVE-2007-5927.
No, CVE-2007-5927 requires authentication to exploit the directory traversal vulnerability.
CVE-2007-5927 can be leveraged to execute arbitrary code through the related vulnerability CVE-2007-5926.