MEDIUM · 5.0

CVE-2007-6361

Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated...

Vulnerability Description

Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.

CVSS Score

5.0

MEDIUM

AV:N/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
GekkowareGekko<= 0.8.2

Related Weaknesses (CWE)

References

FAQ

What is CVE-2007-6361?

CVE-2007-6361 is a vulnerability with a CVSS score of 5.0 (MEDIUM). Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated...

How severe is CVE-2007-6361?

CVE-2007-6361 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2007-6361?

Check the references section above for vendor advisories and patch information. Affected products include: Gekkoware Gekko.