CVE-2007-6361
Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries.
Does this matter?
Lower severity and a low EPSS score (1.22%). Track it; it rarely justifies an emergency change on its own.
Description
Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:N/I:P/A:N
- EPSS
- 1.22% probability · 67th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-264
- Affected
- gekkoware/gekko
- Source
- cve@mitre.org
References
- http://osvdb.org/44151
- http://securityreason.com/securityalert/3451
- http://www.securityfocus.com/archive/1/484330/100/0/threaded
- http://www.securityfocus.com/archive/1/484343/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38735
- http://osvdb.org/44151
- http://securityreason.com/securityalert/3451
- http://www.securityfocus.com/archive/1/484330/100/0/threaded
- http://www.securityfocus.com/archive/1/484343/100/0/threaded
- https://exchange.xforce.ibmcloud.com/vulnerabilities/38735
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.