CVE Vulnerabilities

CVE-2007-2747

Published: May 17, 2007 | Modified: Jul 29, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in rdw_helpers.py in rdiffWeb before 0.3.5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter to the /browse URI.

Affected Software

Name Vendor Start Version End Version
Rdiffweb Rdiffweb * 0.3.5 (including)
Rdiffweb Rdiffweb 0.1 (including) 0.1 (including)
Rdiffweb Rdiffweb 0.2 (including) 0.2 (including)
Rdiffweb Rdiffweb 0.3 (including) 0.3 (including)
Rdiffweb Rdiffweb 0.3.1 (including) 0.3.1 (including)
Rdiffweb Rdiffweb 0.3.2 (including) 0.3.2 (including)

References