CVE-2007-6361
Last modified
CVE-2007-6361 is a vulnerability of currently unknown severity. Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.. EPSS estimates a 1.22% chance of exploitation in the next 30 days.
Description
Gekko 0.8.2 and earlier stores sensitive information under the web root with possibly insufficient access control, which might allow remote attackers to read certain files under temp/, as demonstrated by a log file that records the titles of blog entries. NOTE: access to temp/ is blocked by .htaccess in most deployments that use Apache HTTP Server.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Gekkoware | Gekko | <= 0.8.2 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2007-6361?
How severe is CVE-2007-6361?
How do I fix CVE-2007-6361?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2007
- CVE-2007-6355Integer overflow in exiftags before 1.01 has unknown impact …
- CVE-2007-6356exiftags before 1.01 allows attackers to cause a denial of s…
- CVE-2007-6357Stack-based buffer overflow in Microsoft Office Access allow…
- CVE-2007-6358pdftops.pl before 1.20 in alternate pdftops filter allows lo…
- CVE-2007-6359The cs_validate_page function in bsd/kern/ubc_subr.c in the …
- CVE-2007-6360Unspecified vulnerability in the Sun eXtended System Control…
- CVE-2007-6362SQL injection vulnerability in index.php in the RSGallery (c…
- CVE-2007-6363IBM Tivoli Netcool Security Manager 1.3.0 before Interim Fix…
- CVE-2007-6364Cross-site scripting (XSS) vulnerability in modificarPerfil.…
- CVE-2007-6365Cross-site scripting (XSS) vulnerability in modules/ecal/dis…
- CVE-2007-6366Multiple SQL injection vulnerabilities in SineCMS 2.3.4 and …
- CVE-2007-6367Multiple cross-site scripting (XSS) vulnerabilities in the g…
Are you affected by CVE-2007-6361?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
