5

CVE-2007-2048

Exploit
Directory traversal vulnerability in /console in the Management Console in webMethods Glue 6.5.1 and earlier allows remote attackers to read arbitrary system files via a .. (dot dot) in the resource parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
WebmethodsGlue Version4.0
WebmethodsGlue Version5.0
WebmethodsGlue Version6.5.1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.83% 0.887
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/24933
http://securityreason.com/securityalert/2589
http://www.aushack.com/advisories/200704-webmethods.txt
Exploit
http://www.securityfocus.com/archive/1/465332/100/0/threaded
http://www.securityfocus.com/archive/1/465993/100/0/threaded
http://www.securityfocus.com/archive/1/467873/30/6720/threaded
http://www.securityfocus.com/bid/23423
Exploit
http://www.securitytracker.com/id?1017926
http://www.vupen.com/english/advisories/2007/1363