CVE-2007-4655
Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal sequences in unspecified parameters…
Does this matter?
Lower severity and a low EPSS score (1.84%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal sequences in unspecified parameters to (1) list.cgi or (2) list2.cgi.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.84% probability · 78th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22, CWE-200
- Affected
- cgi-rescue/shopping basket professional
- Source
- cve@mitre.org
References
- http://jvn.jp/jp/JVN%2320452446/index.html
- http://osvdb.org/40146
- http://osvdb.org/40147
- http://secunia.com/advisories/26614Vendor Advisory
- http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20070823212803
- http://www.securityfocus.com/bid/25500
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36389
- http://jvn.jp/jp/JVN%2320452446/index.html
- http://osvdb.org/40146
- http://osvdb.org/40147
- http://secunia.com/advisories/26614Vendor Advisory
- http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20070823212803
- http://www.securityfocus.com/bid/25500
- https://exchange.xforce.ibmcloud.com/vulnerabilities/36389
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.