Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2008-0252

Опубликовано: 12 янв. 2008
Источник: nvd
CVSS2: 7.5
EPSS Низкий

Описание

Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py in CherryPy 2.1, and (3) filter/sessionfilter.py in CherryPy 2.x allows remote attackers to create or delete arbitrary files, and possibly read and write portions of arbitrary files, via a crafted session id in a cookie.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:cherrypy:cherrypy:*:*:*:*:*:*:*:*
Версия до 2.1.0 (включая)
cpe:2.3:a:cherrypy:cherrypy:*:*:*:*:*:*:*:*
Версия до 3.0.2 (включая)

EPSS

Процентиль: 83%
0.01961
Низкий

7.5 High

CVSS2

Дефекты

CWE-22

Связанные уязвимости

ubuntu
почти 18 лет назад

Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py in CherryPy 2.1, and (3) filter/sessionfilter.py in CherryPy 2.x allows remote attackers to create or delete arbitrary files, and possibly read and write portions of arbitrary files, via a crafted session id in a cookie.

debian
почти 18 лет назад

Directory traversal vulnerability in the _get_file_path function in (1 ...

CVSS3: 7.5
github
больше 3 лет назад

CherryPy Malicious cookies allow access to files outside the session directory

EPSS

Процентиль: 83%
0.01961
Низкий

7.5 High

CVSS2

Дефекты

CWE-22