Bugsalert.com
Security News about Viruses, Spyware,
Trojans, Malware, XSS attacks.

CVE-2008-0466 (Text Editor)

BugsAlert Home > CVE-2008-0466 (Text Editor)
 
 

RTE_file_browser.asp in Web Wiz Rich Text Editor 4.0 does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a separate directory traversal vulnerability.




Original Source: http://nvd.nist.gov/nvd.cfm?cvename=CVE-2008-0466

Learn more about CVE-2008-0466 (Text Editor)
 
Tags: cve-2008-0466 text editor

Related Items

      Joomla 1.0.13 - 1.0.14 / (remote) PHP file inclusion possible if old configuration.php

      Chinese define what is malicious software

      Wardriving in Monterrey — Mexico

      VU#305208: Caucho Resin vulnerable to XSS via "file" parameter to "viewfile"

      Gentoo update for paramiko

      Fedora Security Update Fixes Mono Big Integer Buffer Overflow Issue

      CVE-2008-3293 (EZWebAlbum)

 

Pixel