VulnerabilityModified
CVE-2008-3939
Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.
HIGH 7.5EPSS 1.70%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.70%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Directory traversal vulnerability in the web interface in AVTECH PageR Enterprise before 5.0.7 allows remote attackers to read arbitrary files via directory traversal sequences in the URI.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
- EPSS
- 1.70% probability · 76th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- avtech/pager enterprise
- Source
- cve@mitre.org
References
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-September/064227.html
- http://secunia.com/advisories/31693Vendor Advisory
- http://www.securityfocus.com/bid/30987
- http://lists.grok.org.uk/pipermail/full-disclosure/2008-September/064227.html
- http://secunia.com/advisories/31693Vendor Advisory
- http://www.securityfocus.com/bid/30987
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.