CVE-2007-0450
45Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 91%
from disclosure to weapon0 days
Published on NVDMar 16
1st PoCMar 14
exploitation probability
91%top 1% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
What the vendors declare (VEX)
Official vendor statements in CSAF/VEX format: whether their product is affected, already fixed, or ruled out — and why. These are the vendor's assertions, not Vexday's judgment.
Red HatVEX document ↗
Fixed
21 products (462 components)
Red Hat Enterprise Linux (v. 5 server) · Red Hat Enterprise Linux Desktop Workstation (v. 5 client) · Red Hat Enterprise Linux Desktop (v. 5 client) · Red Hat Certificate System 7.3 for 4AS · Red Hat Certificate System 7.3 for 4ES · and others 16
Not affected
2 products (4 components) — because the vulnerable code is not present in the product
Red Hat Application Stack v1 for Enterprise Linux AS (v.4) · Red Hat Application Stack v1 for Enterprise Linux ES (v.4)
Directory traversal vulnerability in Apache HTTP Server and Tomcat 5.x before 5.5.22 and 6.x before 6.0.10, when using certain proxy modules (mod_proxy, mod_rewrite, mod_jk), allows remote attackers to read arbitrary files via a .. (dot dot) sequence with combinations of (1) "/" (slash), (2) "\" (backslash), and (3) URL-encoded backslash (%5C) characters in the URL, which are valid separators in Tomcat but not in Apache.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/29739⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://community.ca.com/blogs/casecurityresponseblog/archive/2009/01/23.aspxhttp://docs.info.apple.com/article.html?artnum=306172http://h20000.www2.hp.com/bizsupport/TechSupport/Document.jsp?objectID=c01178795http://lists.apple.com/archives/security-announce//2007/Jul/msg00004.htmlhttp://lists.vmware.com/pipermail/security-announce/2008/000003.htmlhttp://secunia.com/advisories/24732http://secunia.com/advisories/25106http://secunia.com/advisories/25280http://secunia.com/advisories/26235http://secunia.com/advisories/26660http://secunia.com/advisories/27037http://secunia.com/advisories/28365