CVE-2008-6423

Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arbitrary local files via a .. (dot dot) in the site_id parameter.
Path Traversal
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5 UNKNOWN
NETWORK
LOW
AV:N/AC:L/Au:N/C:P/I:N/A:N
mitreCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
i-appspasswiki
𝑥
≤ 0.9.16
i-appspasswiki
0.9.3
i-appspasswiki
0.9.5
i-appspasswiki
0.9.6
i-appspasswiki
0.9.7
i-appspasswiki
0.9.8
i-appspasswiki
0.9.9
i-appspasswiki
0.9.10
i-appspasswiki
0.9.11
i-appspasswiki
0.9.12
i-appspasswiki
0.9.13
i-appspasswiki
0.9.14
i-appspasswiki
0.9.15
i-appspasswiki
0.9.15:beta
i-appspasswiki
0.9.15:beta2
i-appspasswiki
0.9.15:rc1
i-appspasswiki
0.9.16:beta1
i-appspasswiki
0.9.16:beta2
i-appspasswiki
0.9.16:beta3
i-appspasswiki
0.9.16:rc1
i-appspasswiki
0.9.16:rc2
𝑥
= Vulnerable software versions