Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2007-6361

Опубликовано: 15 дек. 2007
Источник: nvd
CVSS2: 5
EPSS Низкий

Описание

Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:gekkoware:gekko:*:*:*:*:*:*:*:*
Версия до 0.8.2 (включая)

EPSS

Процентиль: 55%
0.00329
Низкий

5 Medium

CVSS2

Дефекты

CWE-264

Связанные уязвимости

github
почти 4 года назад

Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.

EPSS

Процентиль: 55%
0.00329
Низкий

5 Medium

CVSS2

Дефекты

CWE-264