Vulnerabilities > CVE-2007-2633 - Directory Traversal vulnerability in Positive Software Sitestudio 1.6

047910
CVSS 10.0 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
positive-software
critical

Summary

Directory traversal vulnerability in H-Sphere SiteStudio 1.6 allows remote attackers to read, or include and execute, arbitrary local files via a .. (dot dot) in the template parameter.

Vulnerable Configurations

Part Description Count
Application
Positive_Software
1