Vulnerabilidad en classtheme.class.php en SPAW Editor PHP Edition (CVE-2008-4358)
Gravedad CVSS v2.0:
ALTA
Tipo:
CWE-20
Validación incorrecta de entrada
Fecha de publicación:
30/09/2008
Última modificación:
09/04/2025
Descripción
Vulnerabilidad sin especificar en class/theme.class.php en SPAW Editor PHP Edition 2.0.8.1 tiene un impacto y vectores de ataque desconocidos, probablemente relacionados con las secuencias transversales de salto de directorio en el nombre "theme".
Impacto
Puntuación base 2.0
10.00
Gravedad 2.0
ALTA
Productos y versiones vulnerables
| CPE | Desde | Hasta |
|---|---|---|
| cpe:2.3:a:spaw_editor:spaw_php:*:*:*:*:*:*:*:* | 2.0.8 (incluyendo) | |
| cpe:2.3:a:spaw_editor:spaw_php:1.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:spaw_editor:spaw_php:1.0:rc1:*:*:*:*:*:* | ||
| cpe:2.3:a:spaw_editor:spaw_php:1.0:rc2:*:*:*:*:*:* | ||
| cpe:2.3:a:spaw_editor:spaw_php:1.0.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:spaw_editor:spaw_php:1.0.2:*:*:*:*:*:*:* | ||
| cpe:2.3:a:spaw_editor:spaw_php:1.0.3:*:*:*:*:*:*:* | ||
| cpe:2.3:a:spaw_editor:spaw_php:1.0.4:*:*:*:*:*:*:* | ||
| cpe:2.3:a:spaw_editor:spaw_php:1.0.5:*:*:*:*:*:*:* | ||
| cpe:2.3:a:spaw_editor:spaw_php:1.0.5a:*:*:*:*:*:*:* | ||
| cpe:2.3:a:spaw_editor:spaw_php:1.0.6:*:*:*:*:*:*:* | ||
| cpe:2.3:a:spaw_editor:spaw_php:1.0.7:*:*:*:*:*:*:* | ||
| cpe:2.3:a:spaw_editor:spaw_php:1.1:*:*:*:*:*:*:* | ||
| cpe:2.3:a:spaw_editor:spaw_php:1.1:beta:*:*:*:*:*:* | ||
| cpe:2.3:a:spaw_editor:spaw_php:1.1:rc1:*:*:*:*:*:* |
Para consultar la lista completa de nombres de CPE con productos y versiones, ver esta página
Referencias a soluciones, herramientas e información
- http://blog.solmetra.com/2008/09/10/spaw-editor-php-edition-hotfix-release/
- http://secunia.com/advisories/31796
- http://sourceforge.net/project/shownotes.php?release_id=625333&group_id=77954
- http://spaw.svn.sourceforge.net/viewvc/spaw/spaw2/trunk/class/theme.class.php?r1=151&r2=359
- http://www.securityfocus.com/bid/31185
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45104
- http://blog.solmetra.com/2008/09/10/spaw-editor-php-edition-hotfix-release/
- http://secunia.com/advisories/31796
- http://sourceforge.net/project/shownotes.php?release_id=625333&group_id=77954
- http://spaw.svn.sourceforge.net/viewvc/spaw/spaw2/trunk/class/theme.class.php?r1=151&r2=359
- http://www.securityfocus.com/bid/31185
- https://exchange.xforce.ibmcloud.com/vulnerabilities/45104



