Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

ubuntu логотип

CVE-2008-4437

Опубликовано: 03 окт. 2008
Источник: ubuntu
Приоритет: medium
CVSS2: 7.1

Описание

Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.

РелизСтатусПримечание
dapper

not-affected

devel

not-affected

3.2.0.0~rc2-1
feisty

ignored

end of life, was needed
gutsy

released

2.22.1-2.2ubuntu1.7.10.1
hardy

released

2.22.1-2.2ubuntu1.8.04.1
intrepid

released

3.0.4.1-2ubuntu1.1
upstream

released

3.0.5

Показывать по

Ссылки на источники

7.1 High

CVSS2

Связанные уязвимости

redhat
почти 17 лет назад

Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.

nvd
почти 17 лет назад

Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.

debian
почти 17 лет назад

Directory traversal vulnerability in importxml.pl in Bugzilla before 2 ...

github
больше 3 лет назад

Directory traversal vulnerability in importxml.pl in Bugzilla before 2.22.5, and 3.x before 3.0.5, when --attach_path is enabled, allows remote attackers to read arbitrary files via an XML file with a .. (dot dot) in the data element.

7.1 High

CVSS2