Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2007-6290 (SERWeb)

BugsAlert Home > CVE-2007-6290 (SERWeb)
 
 

Multiple directory traversal vulnerabilities in js/get_js.php in SERWeb 2.0.0 dev1 and earlier allow remote attackers to read arbitrary files via a .. (dot dot) in the (1) mod and (2) js parameters.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2007-6290

Learn more about CVE-2007-6290 (SERWeb)
 
Tags: cve-2007-6290 serweb

Related Items

      Sun Java System LDAP JDK Information Disclosure Vulnerability

      Open Media Collectors Database Cross-Site Scripting and Request Forgery

      CVE-2007-4474 (Lotus Domino Web Access)

      CVE-2008-3402 (hiox_random_ad)

      VU#568681:AOL Radio AOLMediaPlaybackControl.exe stack buffer overflow

      Trojan-Downloader.Win32.Small.bah

      Bugtraq: [security bulletin] HPSBTU02383 SSRT080098 rev.1 - HP Tru64 UNIX running AdvFS "showfile" command, Local Gain Extended Privileges

 

Pixel