6.8

CVE-2010-0403

Directory traversal vulnerability in about.php in phpGroupWare (phpgw) before 0.9.16.016 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the app parameter.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
PhpgroupwarePhpgroupware Version <= 0.9.16.015
PhpgroupwarePhpgroupware Version0.9.16
PhpgroupwarePhpgroupware Version0.9.16.000
PhpgroupwarePhpgroupware Version0.9.16.001
PhpgroupwarePhpgroupware Version0.9.16.002
PhpgroupwarePhpgroupware Version0.9.16.003
PhpgroupwarePhpgroupware Version0.9.16.005
PhpgroupwarePhpgroupware Version0.9.16.010
PhpgroupwarePhpgroupware Version0.9.16.011
PhpgroupwarePhpgroupware Version0.9.16.012
PhpgroupwarePhpgroupware Version0.9.16.014
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.98% 0.779
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

http://download.phpgroupware.org/
Patch
Vendor Advisory
http://forums.phpgroupware.org/index.php?t=msg&th=98662&start=0&rid=0
Patch
http://lists.gnu.org/archive/html/phpgroupware-users/2010-05/msg00004.html
http://secunia.com/advisories/39665
Vendor Advisory
http://secunia.com/advisories/39731
Vendor Advisory
http://www.debian.org/security/2010/dsa-2046
http://www.securityfocus.com/archive/1/511299/100/0/threaded
http://www.securityfocus.com/bid/40167
http://www.vupen.com/english/advisories/2010/1145
Patch
Vendor Advisory
http://www.vupen.com/english/advisories/2010/1146
Vendor Advisory
https://exchange.xforce.ibmcloud.com/vulnerabilities/58657