CVE-2008-6522
Multiple directory traversal vulnerabilities in the RenderFile function in ContentRender.class.php in Terracotta (aka OpenTerracotta) 0.6.1, and possibly other versions, allow remote attackers to list arbitrary directories and read arbitrary files via a…
Does this matter?
Lower severity and a low EPSS score (1.90%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple directory traversal vulnerabilities in the RenderFile function in ContentRender.class.php in Terracotta (aka OpenTerracotta) 0.6.1, and possibly other versions, allow remote attackers to list arbitrary directories and read arbitrary files via a .. (dot dot) in the (1) CurrentDirectory and (2) File parameters to index.php.
- CVSS 2.0
- 6.8 MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
- EPSS
- 1.90% probability · 79th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-22
- Affected
- devraj mukherjee/openterracotta
- Source
- cve@mitre.org
References
- http://www.securityfocus.com/archive/1/490341/100/0/threaded
- http://www.securityfocus.com/bid/28550Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41572
- http://www.securityfocus.com/archive/1/490341/100/0/threaded
- http://www.securityfocus.com/bid/28550Exploit
- https://exchange.xforce.ibmcloud.com/vulnerabilities/41572
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.