[prev in list] [next in list] [prev in thread] [next in thread] 

List:       oss-security
Subject:    [oss-security] [CVE-2019-0225] Apache JSPWiki Local File Inclusion (limited ROOT folder) vulnerabili
From:       Juan_Pablo_Santos_Rodríguez <juanpablo () apache ! org>
Date:       2019-03-26 21:43:09
Message-ID: CAMufup6J2t4fA1ffPKTqBJvSmqbJbdUxPtbcUS1faVU_NthnvQ () mail ! gmail ! com
[Download RAW message or body]


[CVEID]:CVE-2019-0225
[PRODUCT]:Apache JSPWiki
[VERSION]:Apache JSPWiki 2.9.0 to 2.11.0.M2
[PROBLEMTYPE]:Local File Inclusion (limited ROOT folder) vulnerability
leads to user information disclosure
[REFERENCES]:https://jspwiki-wiki.apache.org/Wiki.jsp?page=CVE-2019-0225
[DESCRIPTION]: A specially crafted url could be used to access files under
the ROOT directory of the application on Apache JSPWiki, which could be
used by an attacker to obtain registered users' details.


[prev in list] [next in list] [prev in thread] [next in thread] 

Configure | About | News | Add a list | Sponsored by KoreLogic