CVE-2008-6423

Severity CVSS v4.0:
Pending analysis
Type:
CWE-22 Path Traversal
Publication date:
06/03/2009
Last modified:
29/09/2017

Description

Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arbitrary local files via a .. (dot dot) in the site_id parameter.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:i-apps:passwiki:*:rc3:*:*:*:*:*:* 0.9.16 (including)
cpe:2.3:a:i-apps:passwiki:0.9.3:*:*:*:*:*:*:*
cpe:2.3:a:i-apps:passwiki:0.9.5:*:*:*:*:*:*:*
cpe:2.3:a:i-apps:passwiki:0.9.6:*:*:*:*:*:*:*
cpe:2.3:a:i-apps:passwiki:0.9.7:*:*:*:*:*:*:*
cpe:2.3:a:i-apps:passwiki:0.9.8:*:*:*:*:*:*:*
cpe:2.3:a:i-apps:passwiki:0.9.9:*:*:*:*:*:*:*
cpe:2.3:a:i-apps:passwiki:0.9.10:*:*:*:*:*:*:*
cpe:2.3:a:i-apps:passwiki:0.9.11:*:*:*:*:*:*:*
cpe:2.3:a:i-apps:passwiki:0.9.12:*:*:*:*:*:*:*
cpe:2.3:a:i-apps:passwiki:0.9.13:*:*:*:*:*:*:*
cpe:2.3:a:i-apps:passwiki:0.9.14:*:*:*:*:*:*:*
cpe:2.3:a:i-apps:passwiki:0.9.15:*:*:*:*:*:*:*
cpe:2.3:a:i-apps:passwiki:0.9.15:beta:*:*:*:*:*:*
cpe:2.3:a:i-apps:passwiki:0.9.15:beta2:*:*:*:*:*:*