CVE-2008-6786

Multiple directory traversal vulnerabilities in geekigeeki.py in GeekiGeeki before 3.0 allow remote attackers to read arbitrary files via directory traversal sequences in a pagename argument in the (1) handle_edit and (2) handle_raw functions.
Configurations

Configuration 1 (hide)

cpe:2.3:a:codewiz:geekigeeki:2.0:*:*:*:*:*:*:*

History

21 Nov 2024, 00:57

Type Values Removed Values Added
References () http://secunia.com/advisories/33162 - Vendor Advisory () http://secunia.com/advisories/33162 - Vendor Advisory
References () http://www.codewiz.org/wikigit/geekigeeki.git/blobdiff/92e45c3ce9260c69b4201d877c0f2e431024a52e..5f99f96a7a102bb8f2c491dd1e11fe8686c7c0a0:/geekigeeki.py - Exploit () http://www.codewiz.org/wikigit/geekigeeki.git/blobdiff/92e45c3ce9260c69b4201d877c0f2e431024a52e..5f99f96a7a102bb8f2c491dd1e11fe8686c7c0a0:/geekigeeki.py - Exploit
References () http://www.codewiz.org/wikigit/geekigeeki.git?a=commit%3Bh=5f99f96a7a102bb8f2c491dd1e11fe8686c7c0a0 - () http://www.codewiz.org/wikigit/geekigeeki.git?a=commit%3Bh=5f99f96a7a102bb8f2c491dd1e11fe8686c7c0a0 -
References () http://www.osvdb.org/50719 - Patch () http://www.osvdb.org/50719 - Patch
References () http://www.securityfocus.com/bid/32831 - Patch () http://www.securityfocus.com/bid/32831 - Patch
References () https://exchange.xforce.ibmcloud.com/vulnerabilities/47375 - () https://exchange.xforce.ibmcloud.com/vulnerabilities/47375 -

07 Nov 2023, 02:03

Type Values Removed Values Added
References
  • {'url': 'http://www.codewiz.org/wikigit/geekigeeki.git?a=commit;h=5f99f96a7a102bb8f2c491dd1e11fe8686c7c0a0', 'name': 'http://www.codewiz.org/wikigit/geekigeeki.git?a=commit;h=5f99f96a7a102bb8f2c491dd1e11fe8686c7c0a0', 'tags': ['Patch'], 'refsource': 'CONFIRM'}
  • () http://www.codewiz.org/wikigit/geekigeeki.git?a=commit%3Bh=5f99f96a7a102bb8f2c491dd1e11fe8686c7c0a0 -

Information

Published : 2009-05-01 18:30

Updated : 2024-11-21 00:57


NVD link : CVE-2008-6786

Mitre link : CVE-2008-6786

CVE.ORG link : CVE-2008-6786


JSON object : View

Products Affected

codewiz

  • geekigeeki
CWE
CWE-22

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')