CVE Database
/

CVE-2007-6361

Back to search

CVE-2007-6361

Published: Dec 15, 2007

Modified: Aug 7, 2024

PUBLISHED

Description

Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.

VendorProductVersions

n/a

n/a

affected
n/a

References

3451
third-party-advisory
x_refsource_SREASON
44151
vdb-entry
x_refsource_OSVDB

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now