CVE-2007-0585
include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conffile parameter.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.97%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
include/debug.php in Webfwlog 0.92 and earlier, when register_globals is enabled, allows remote attackers to obtain source code of files via the conffile parameter. NOTE: some of these details are obtained from third party information. It is likely that this issue can be exploited to conduct directory traversal attacks.
- CVSS 2.0
- 9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 3.97% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- webfwlog/webfwlog
- Source
- cve@mitre.org
References
- http://osvdb.org/33015
- http://secunia.com/advisories/23968
- http://webfwlog.cvs.sourceforge.net/%2Acheckout%2A/webfwlog/webfwlog/ChangeLog
- http://www.securityfocus.com/bid/22291
- http://www.vupen.com/english/advisories/2007/0399
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31881
- https://www.exploit-db.com/exploits/3222
- http://osvdb.org/33015
- http://secunia.com/advisories/23968
- http://webfwlog.cvs.sourceforge.net/%2Acheckout%2A/webfwlog/webfwlog/ChangeLog
- http://www.securityfocus.com/bid/22291
- http://www.vupen.com/english/advisories/2007/0399
- https://exchange.xforce.ibmcloud.com/vulnerabilities/31881
- https://www.exploit-db.com/exploits/3222
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.