CVE-2007-6268
23Vexday Risk Score
No sign of exploitation. It has a public proof of concept.
ssvc Attendepss 8.4%
from disclosure to weapon0 days
Published on NVDDec 7
1st PoCDec 4
exploitation probability
8.4%top 6% of all CVEs
observed exploitation
nono source reports it
1 public exploit(s)
Directory traversal vulnerability in pages/default.aspx in Absolute News Manager.NET 5.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the template parameter.
Affected products
n/a · n/apublic PoCs found — 1✓ VexDay Proof
exploitdb✓ VexDay Proofwww.exploit-db.com/exploits/30841⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.
References
http://marc.info/?l=bugtraq&m=119678724111351&w=2http://osvdb.org/40575http://secunia.com/advisories/27923https://exchange.xforce.ibmcloud.com/vulnerabilities/38870http://www.procheckup.com/Vulnerability_PR07-39.phphttp://www.securityfocus.com/bid/26692http://www.xigla.com/news/default.aspxhttp://www.xigla.com/security/ANMNET51-SecurityUpdate20071128.zip