First published: Tue Mar 18 2008(Updated: )
Directory traversal vulnerability in ContentServer.py in the Wiki Server in Apple Mac OS X 10.5.2 (aka Leopard) allows remote authenticated users to write arbitrary files via ".." sequences in file attachments.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Apple Mac OS X Server | =10.5.2 | |
macOS Yosemite | =10.5.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2008-1000 is considered high due to potential unauthorized file write access.
To fix CVE-2008-1000, update Apple Mac OS X to the latest version available that addresses this vulnerability.
CVE-2008-1000 affects Apple Mac OS X 10.5.2 users, including both server and standard versions.
CVE-2008-1000 can allow remote authenticated users to manipulate the file system, leading to potential data breaches.
As a workaround for CVE-2008-1000, restrict access to the Wiki Server for untrusted users until a patch is applied.