fkie_cve-2008-3195
Vulnerability from fkie_nvd
Published
2008-09-18 15:04
Modified
2025-04-09 00:30
Severity ?
Summary
Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files via a query string containing a .. (dot dot) in the image variable, and execute arbitrary files via unspecified vectors.
References
cve@mitre.orghttp://secunia.com/advisories/31849
cve@mitre.orghttp://secunia.com/advisories/31964
cve@mitre.orghttp://securityreason.com/securityalert/4265
cve@mitre.orghttp://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2008-3195Patch
cve@mitre.orghttp://twiki.org/cgi-bin/view/Codev/TWikiRelease04x02x03#4_2_3_Bugfix_HighlightsPatch
cve@mitre.orghttp://www.kb.cert.org/vuls/id/362012US Government Resource
cve@mitre.orghttp://www.kb.cert.org/vuls/id/RGII-7JEQ7L
cve@mitre.orghttp://www.vupen.com/english/advisories/2008/2586
cve@mitre.orghttps://exchange.xforce.ibmcloud.com/vulnerabilities/45182
cve@mitre.orghttps://exchange.xforce.ibmcloud.com/vulnerabilities/45183
cve@mitre.orghttps://www.exploit-db.com/exploits/6269
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/31849
af854a3a-2127-422b-91ae-364da2661108http://secunia.com/advisories/31964
af854a3a-2127-422b-91ae-364da2661108http://securityreason.com/securityalert/4265
af854a3a-2127-422b-91ae-364da2661108http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2008-3195Patch
af854a3a-2127-422b-91ae-364da2661108http://twiki.org/cgi-bin/view/Codev/TWikiRelease04x02x03#4_2_3_Bugfix_HighlightsPatch
af854a3a-2127-422b-91ae-364da2661108http://www.kb.cert.org/vuls/id/362012US Government Resource
af854a3a-2127-422b-91ae-364da2661108http://www.kb.cert.org/vuls/id/RGII-7JEQ7L
af854a3a-2127-422b-91ae-364da2661108http://www.vupen.com/english/advisories/2008/2586
af854a3a-2127-422b-91ae-364da2661108https://exchange.xforce.ibmcloud.com/vulnerabilities/45182
af854a3a-2127-422b-91ae-364da2661108https://exchange.xforce.ibmcloud.com/vulnerabilities/45183
af854a3a-2127-422b-91ae-364da2661108https://www.exploit-db.com/exploits/6269
Impacted products
Vendor Product Version
twiki twiki *
twiki twiki 4.0
twiki twiki 4.0.0
twiki twiki 4.0.1
twiki twiki 4.0.2
twiki twiki 4.0.3
twiki twiki 4.0.4
twiki twiki 4.0.5
twiki twiki 4.1.0
twiki twiki 4.1.1
twiki twiki 4.1.2
twiki twiki 4.2.0
twiki twiki 4.2.1



{
  "configurations": [
    {
      "nodes": [
        {
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:twiki:twiki:*:*:*:*:*:*:*:*",
              "matchCriteriaId": "92E06542-B556-44C0-901A-0380F09741DE",
              "versionEndIncluding": "4.2.2",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:twiki:twiki:4.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "A0E0A8F3-02EE-4A6D-BAAC-1D52DF063197",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:twiki:twiki:4.0.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "F893E121-82FA-41C8-9BA4-606E6DA01408",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:twiki:twiki:4.0.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "47807C3A-8430-48E3-A7C8-C5A1FEDF84C0",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:twiki:twiki:4.0.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "620356EA-F106-41DF-AADA-C1EF5A5A0829",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:twiki:twiki:4.0.3:*:*:*:*:*:*:*",
              "matchCriteriaId": "979D8BC8-0032-496F-9503-F3BBBC8FA7CF",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:twiki:twiki:4.0.4:*:*:*:*:*:*:*",
              "matchCriteriaId": "0804FF93-6554-4F56-9974-017198ED5F44",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:twiki:twiki:4.0.5:*:*:*:*:*:*:*",
              "matchCriteriaId": "41445C95-0309-4B90-B725-87D2FE87C9A5",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:twiki:twiki:4.1.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "C9996E5B-36AD-407F-B3B6-839CE8E5913E",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:twiki:twiki:4.1.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "748325A4-A237-498A-A185-905FC921D2A3",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:twiki:twiki:4.1.2:*:*:*:*:*:*:*",
              "matchCriteriaId": "9FE3EEC6-7E05-4A37-97AA-D73E7D7A0E01",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:twiki:twiki:4.2.0:*:*:*:*:*:*:*",
              "matchCriteriaId": "855671F5-C215-4382-B512-4ABD9D66F13D",
              "vulnerable": true
            },
            {
              "criteria": "cpe:2.3:a:twiki:twiki:4.2.1:*:*:*:*:*:*:*",
              "matchCriteriaId": "E9C00515-CFEE-427A-BACE-B3140B0D6C67",
              "vulnerable": true
            }
          ],
          "negate": false,
          "operator": "OR"
        }
      ]
    }
  ],
  "cveTags": [],
  "descriptions": [
    {
      "lang": "en",
      "value": "Directory traversal vulnerability in bin/configure in TWiki before 4.2.3, when a certain step in the installation guide is skipped, allows remote attackers to read arbitrary files via a query string containing a .. (dot dot) in the image variable, and execute arbitrary files via unspecified vectors."
    },
    {
      "lang": "es",
      "value": "Vulnerabilidad de salto de directorio en bin/configure en TWiki anterior a v4.2.3, cuando alg\u00fan paso en el asistente de instalaci\u00f3n es omitido, permite a atacantes remotos leer ficheros de su elecci\u00f3n a trav\u00e9s de una cadena de consulta que contiene ..(punto punto) en la variable \"image\", y ejecutar archivos de su elecci\u00f3n a trav\u00e9s de vectores no especificados."
    }
  ],
  "id": "CVE-2008-3195",
  "lastModified": "2025-04-09T00:30:58.490",
  "metrics": {
    "cvssMetricV2": [
      {
        "acInsufInfo": false,
        "baseSeverity": "MEDIUM",
        "cvssData": {
          "accessComplexity": "MEDIUM",
          "accessVector": "NETWORK",
          "authentication": "NONE",
          "availabilityImpact": "PARTIAL",
          "baseScore": 6.8,
          "confidentialityImpact": "PARTIAL",
          "integrityImpact": "PARTIAL",
          "vectorString": "AV:N/AC:M/Au:N/C:P/I:P/A:P",
          "version": "2.0"
        },
        "exploitabilityScore": 8.6,
        "impactScore": 6.4,
        "obtainAllPrivilege": false,
        "obtainOtherPrivilege": true,
        "obtainUserPrivilege": false,
        "source": "nvd@nist.gov",
        "type": "Primary",
        "userInteractionRequired": false
      }
    ]
  },
  "published": "2008-09-18T15:04:27.233",
  "references": [
    {
      "source": "cve@mitre.org",
      "url": "http://secunia.com/advisories/31849"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://secunia.com/advisories/31964"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://securityreason.com/securityalert/4265"
    },
    {
      "source": "cve@mitre.org",
      "tags": [
        "Patch"
      ],
      "url": "http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2008-3195"
    },
    {
      "source": "cve@mitre.org",
      "tags": [
        "Patch"
      ],
      "url": "http://twiki.org/cgi-bin/view/Codev/TWikiRelease04x02x03#4_2_3_Bugfix_Highlights"
    },
    {
      "source": "cve@mitre.org",
      "tags": [
        "US Government Resource"
      ],
      "url": "http://www.kb.cert.org/vuls/id/362012"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.kb.cert.org/vuls/id/RGII-7JEQ7L"
    },
    {
      "source": "cve@mitre.org",
      "url": "http://www.vupen.com/english/advisories/2008/2586"
    },
    {
      "source": "cve@mitre.org",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45182"
    },
    {
      "source": "cve@mitre.org",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45183"
    },
    {
      "source": "cve@mitre.org",
      "url": "https://www.exploit-db.com/exploits/6269"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://secunia.com/advisories/31849"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://secunia.com/advisories/31964"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://securityreason.com/securityalert/4265"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Patch"
      ],
      "url": "http://twiki.org/cgi-bin/view/Codev/SecurityAlert-CVE-2008-3195"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "Patch"
      ],
      "url": "http://twiki.org/cgi-bin/view/Codev/TWikiRelease04x02x03#4_2_3_Bugfix_Highlights"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "tags": [
        "US Government Resource"
      ],
      "url": "http://www.kb.cert.org/vuls/id/362012"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.kb.cert.org/vuls/id/RGII-7JEQ7L"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "http://www.vupen.com/english/advisories/2008/2586"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45182"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://exchange.xforce.ibmcloud.com/vulnerabilities/45183"
    },
    {
      "source": "af854a3a-2127-422b-91ae-364da2661108",
      "url": "https://www.exploit-db.com/exploits/6269"
    }
  ],
  "sourceIdentifier": "cve@mitre.org",
  "vulnStatus": "Deferred",
  "weaknesses": [
    {
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ],
      "source": "nvd@nist.gov",
      "type": "Primary"
    }
  ]
}


Log in or create an account to share your comment.




Tags
Taxonomy of the tags.


Loading…

Loading…

Loading…

Sightings

Author Source Type Date

Nomenclature

  • Seen: The vulnerability was mentioned, discussed, or seen somewhere by the user.
  • Confirmed: The vulnerability is confirmed from an analyst perspective.
  • Exploited: This vulnerability was exploited and seen by the user reporting the sighting.
  • Patched: This vulnerability was successfully patched by the user reporting the sighting.
  • Not exploited: This vulnerability was not exploited or seen by the user reporting the sighting.
  • Not confirmed: The user expresses doubt about the veracity of the vulnerability.
  • Not patched: This vulnerability was not successfully patched by the user reporting the sighting.


Loading…

Loading…