CVE-2008-0252
CVE-2008-0252
Directory traversal vulnerability in the _get_file_path function in (1) lib/sessions.py in CherryPy 3.0.x up to 3.0.2, (2) filter/sessionfilter.py in CherryPy 2.1, and (3) filter/sessionfilter.py in CherryPy 2.x allows remote attackers to create or delete arbitrary files, and possibly read and write portions of arbitrary files, via a crafted session id in a cookie.
Productos afectados
n/a · n/a¿Quieres saber si tu infraestructura está expuesta a esto?
Hablar con TrueHacking →Referencias
https://bugs.gentoo.org/show_bug.cgi?id=204829http://secunia.com/advisories/28353http://secunia.com/advisories/28354http://secunia.com/advisories/28611http://secunia.com/advisories/28620http://secunia.com/advisories/28769http://security.gentoo.org/glsa/glsa-200801-11.xmlhttps://issues.rpath.com/browse/RPL-2127https://www.redhat.com/archives/fedora-package-announce/2008-January/msg00240.htmlhttps://www.redhat.com/archives/fedora-package-announce/2008-January/msg00297.htmlhttp://www.cherrypy.org/changeset/1774http://www.cherrypy.org/changeset/1775