MEDIUM · 4.0

CVE-2007-3018

activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who have restricted accounts, which allows these editors to create files in arbitrary directories.

Vulnerability Description

activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who have restricted accounts, which allows these editors to create files in arbitrary directories.

CVSS Score

4.0

MEDIUM

AV:N/AC:L/Au:S/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
ActivewebContentserver<= 5.6.2929

References

FAQ

What is CVE-2007-3018?

CVE-2007-3018 is a vulnerability with a CVSS score of 4.0 (MEDIUM). activeWeb contentserver CMS before 5.6.2964 does not limit the file-creation ability of editors who have restricted accounts, which allows these editors to create files in arbitrary directories.

How severe is CVE-2007-3018?

CVE-2007-3018 has been rated MEDIUM with a CVSS base score of 4.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-3018?

Check the references section above for vendor advisories and patch information. Affected products include: Activeweb Contentserver.