|
[Japanese]
|
JVNDB-2007-000476
|
Hiki arbitrary file deletion vulnerability
|
Hiki, a Wiki clone software developed by Hiki Development Team, contains a vulnerability that allows a remote attacker to delete arbitrary files.
Hiki contains a vulnerability that allows an arbitrary file to be deleted on a server running Hiki. This is caused by the improper handling of a session management file.
|
Base Metrics:
2.6 (Low)
[IPA Score]
- Access Vector: Network
- Access Complexity: High
- Authentication: None
- Confidentiality Impact: None
- Integrity Impact: Partial
- Availability Impact: None
|
|
|
Hiki Development Team
|
|
A remote attacker may be able to delete arbitrary files with the privilege of the user running Hiki.
|
[Upgrade the software]
The developer has released Hiki 0.8.7 which contains the fix for this vulnerability. We recommend that affected users upgrade their software to the fixed version.
|
Hiki Development Team
|
- Path Traversal(CWE-22) [NVD Evaluation]
|
- CVE-2007-2836
|
- JVN : JVN#05187780
- National Vulnerability Database (NVD) : CVE-2007-2836
- Secunia Advisory : SA25764
- SecurityFocus : 24603
- FrSIRT Advisories : FrSIRT/ADV-2007-2304
|
[2008/05/21]
Web page published
|