CVE-2008-4974

Severity CVSS v4.0:
Pending analysis
Type:
CWE-59 Link Following
Publication date:
06/11/2008
Last modified:
09/04/2025

Description

rrdedit in netmrg 0.20 allows local users to overwrite arbitrary files via a symlink attack on (1) /tmp/*.xml and (2) /tmp/*.backup temporary files.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:netmrg:netmrg:0.20:*:*:*:*:*:*:*