redirect.pl in bk2site 1.1.9 allows local users to overwrite arbitrary files via a symlink attack on the /tmp/redirect.log temporary file. NOTE: this vulnerability is only limited to debug mode, which is disabled by default.
References
Configurations
Information
Published : 2008-11-07 11:36
Updated : 2017-08-07 18:33
NVD link : CVE-2008-4995
Mitre link : CVE-2008-4995
JSON object : View
CWE
CWE-59
Improper Link Resolution Before File Access ('Link Following')
Products Affected
jose_m.vidal
- bk2site