VDB
CVE-2007-5742
CVE-2007-5742
PUBLISHED
CVSS 9 CRITICAL
Directory traversal vulnerability in the WML engine preprocessor for Wesnoth 1.2.x before 1.2.8, and 1.3.x before 1.3.12, allows remote attackers to read arbitrary files via ".." sequences in unknown vectors.
EPSS 1.50% · 81.5th percentile
Risk Scores
CVSS 2.0
9
EPSS Score
1.50%
81.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| wesnoth | wesnoth | 0.8.11, 0.2.1, 0.3 |
| n/a | n/a | n/a |
Timeline
- Dec 1, 2007 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 20, 2022 EPSS Score
- Jul 12, 2022 EPSS Score
- Sep 4, 2022 EPSS Score
- Oct 26, 2022 EPSS Score
- Dec 18, 2022 EPSS Score
- Feb 9, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Apr 3, 2023 EPSS Score
- May 25, 2023 EPSS Score
References
- 41713 vdb
- 27920 third-party-advisory
- FEDORA-2007-3989 vendor-advisory
- http://sourceforge.net/project/shownotes.php?release_id=557098 url
- 27943 third-party-advisory
- 27786 third-party-advisory
- http://www.wesnoth.org/forum/viewtopic.php?p=264289#264289 url
- FEDORA-2007-3986 vendor-advisory
- ADV-2007-4026 vdb
- http://www.wesnoth.org/forum/viewtopic.php?t=18844 url
- wesnoth-wml-directory-traversal(38752) vdb
- 26626 vdb
- DSA-1421 vendor-advisory
- https://nvd.nist.gov/vuln/detail/CVE-2007-5742 advisory