« Volver al listado

CVE-2008-0758

Estado: ModificadaMedia (5)—

Multiple directory traversal vulnerabilities in the Zidget/HTTP embedded HTTP server in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allow remote attackers to read arbitrary (1) gif, (2) png, (3) jpg, (4) xml, (5) ico, (6) zip, and (7) html files via a "..\" (dot dot backslash) sequence in the filename.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (2)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2008-0758",
  "cveTags": [],
  "metrics": {
    "cvssMetricV2": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "version": "2.0",
          "baseScore": 5,
          "accessVector": "NETWORK",
          "vectorString": "AV:N/AC:L/Au:N/C:P/I:N/A:N",
          "authentication": "NONE",
          "integrityImpact": "NONE",
          "accessComplexity": "LOW",
          "availabilityImpact": "NONE",
          "confidentialityImpact": "PARTIAL"
        },
        "acInsufInfo": false,
        "impactScore": 2.9,
        "baseSeverity": "MEDIUM",
        "obtainAllPrivilege": false,
        "exploitabilityScore": 10,
        "obtainUserPrivilege": false,
        "obtainOtherPrivilege": false,
        "userInteractionRequired": false
      }
    ]
  },
  "affected": [
    {
      "source": "cve@mitre.org",
      "affectedData": [
        {
          "vendor": "n/a",
          "product": "n/a",
          "versions": [
            {
              "status": "affected",
              "version": "n/a"
            }
          ]
        }
      ]
    }
  ],
  "published": "2008-02-13T21:00:00.000",
  "references": [
    {
      "url": "http://aluigi.altervista.org/adv/ezipirla-adv.txt",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://aluigi.org/poc/ezipirla.zip",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://secunia.com/advisories/28862",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.grouplogic.com/files/ez/hot/hotFix51.cfm",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/487952/100/0/threaded",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.securityfocus.com/bid/27718",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/0485",
      "source": "cve@mitre.org"
    },
    {
      "url": "http://aluigi.altervista.org/adv/ezipirla-adv.txt",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://aluigi.org/poc/ezipirla.zip",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://secunia.com/advisories/28862",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.grouplogic.com/files/ez/hot/hotFix51.cfm",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/archive/1/487952/100/0/threaded",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.securityfocus.com/bid/27718",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "http://www.vupen.com/english/advisories/2008/0485",
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "Multiple directory traversal vulnerabilities in the Zidget/HTTP embedded HTTP server in ExtremeZ-IP File and Print Server 5.1.2x15 and earlier allow remote attackers to read arbitrary (1) gif, (2) png, (3) jpg, (4) xml, (5) ico, (6) zip, and (7) html files via a \"..\\\" (dot dot backslash) sequence in the filename."
    },
    {
      "lang": "es",
      "value": "Múltiples vulnerabilidades de salto de directorio en el Servidor embebido http Zidget/HTTP de ExtremeZ -IP File and Print Server 5.1.2x15 y versiones anteriores, permiten a un atacante remoto leer ficheros de su elección (1) gif, (2) png, (3) jpg, (4) xml, (5) ico, (6) zip y (7) HTML a traves de una secuencia “..\\.” (punto punto contrabarra punto) en el nombre de archivo."
    }
  ],
  "lastModified": "2026-06-16T22:50:17.687",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:group_logic:extremez-ip_file_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "0A49B207-5051-4BC8-821B-8BB4380C7B78",
              "versionEndIncluding": "5.1.2"
            },
            {
              "criteria": "cpe:2.3:a:group_logic:extremez-ip_print_server:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5702E66B-8AA5-4E53-BF77-2BC24C266C20",
              "versionEndIncluding": "5.1.2"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "vendorComments": [
    {
      "comment": "Group Logic has fixed this issue in the ExtremeZ-IP 5.1.3x03 hotfix released on February 20, 2008. The update is free for all customers with active service contracts who own a version 5.x license and can be downloaded from http://www.grouplogic.com/files/ez/hot/hotFix51.cfm",
      "lastModified": "2008-02-21T00:00:00",
      "organization": "Group Logic"
    }
  ],
  "sourceIdentifier": "cve@mitre.org"
}