CVE-2008-6423
06.03.2009, 18:30
Directory traversal vulnerability in passwiki.php in PassWiki 0.9.16 RC3 and earlier allows remote attackers to read arbitrary local files via a .. (dot dot) in the site_id parameter.
| Vendor | Product | Version |
|---|---|---|
| i-apps | passwiki | 𝑥 ≤ 0.9.16 |
| i-apps | passwiki | 0.9.3 |
| i-apps | passwiki | 0.9.5 |
| i-apps | passwiki | 0.9.6 |
| i-apps | passwiki | 0.9.7 |
| i-apps | passwiki | 0.9.8 |
| i-apps | passwiki | 0.9.9 |
| i-apps | passwiki | 0.9.10 |
| i-apps | passwiki | 0.9.11 |
| i-apps | passwiki | 0.9.12 |
| i-apps | passwiki | 0.9.13 |
| i-apps | passwiki | 0.9.14 |
| i-apps | passwiki | 0.9.15 |
| i-apps | passwiki | 0.9.15:beta |
| i-apps | passwiki | 0.9.15:beta2 |
| i-apps | passwiki | 0.9.15:rc1 |
| i-apps | passwiki | 0.9.16:beta1 |
| i-apps | passwiki | 0.9.16:beta2 |
| i-apps | passwiki | 0.9.16:beta3 |
| i-apps | passwiki | 0.9.16:rc1 |
| i-apps | passwiki | 0.9.16:rc2 |
𝑥
= Vulnerable software versions
References