MEDIUM · 5.5

CVE-2007-6317

Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..\ (dot dot backslash) sequences in the URL path, o...

Vulnerability Description

Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..\ (dot dot backslash) sequences in the URL path, or (2) remote authenticated users to delete arbitrary files or create arbitrary directories via a ..\ (dot dot backslash) sequence in the dir parameter to /drive/c/bdusers/USER/.

CVSS Score

5.5

MEDIUM

AV:N/AC:L/Au:S/C:P/I:P/A:N
Confidentiality
PARTIAL
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
Real Time LogicBarracudadrive Web Server3.7.2
Real Time LogicBarracudadrive Web Server Home Server3.7.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-6317?

CVE-2007-6317 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Multiple directory traversal vulnerabilities in BarracudaDrive Web Server before 3.8 allow (1) remote attackers to read arbitrary files via certain ..\ (dot dot backslash) sequences in the URL path, o...

How severe is CVE-2007-6317?

CVE-2007-6317 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-6317?

Check the references section above for vendor advisories and patch information. Affected products include: Real Time Logic Barracudadrive Web Server, Real Time Logic Barracudadrive Web Server Home Server.