CVE-2007-2836
Summary
| CVE | CVE-2007-2836 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2007-07-02 19:30:00 UTC |
| Updated | 2026-04-23 00:35:47 UTC |
| Description | Directory traversal vulnerability in session.rb in Hiki 0.8.0 through 0.8.6 allows remote attackers to delete arbitrary files via directory traversal sequences in the session ID, which is matched against an insufficiently restrictive regular expression before it is used to construct a filename that is marked for deletion at logout. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Hiki | Hiki | 0.8.0 | All | All | All |
| Application | Hiki | Hiki | 0.8.1 | All | All | All |
| Application | Hiki | Hiki | 0.8.2 | All | All | All |
| Application | Hiki | Hiki | 0.8.3 | All | All | All |
| Application | Hiki | Hiki | 0.8.4 | All | All | All |
| Application | Hiki | Hiki | 0.8.5 | All | All | All |
| Application | Hiki | Hiki | 0.8.6 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Hiki Session ID File Deletion Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Debian update for hiki - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| Hiki - Hiki Advisory 2007-06-24 | af854a3a-2127-422b-91ae-364da2661108 | hikiwiki.org | |
| osvdb.org/37469 | af854a3a-2127-422b-91ae-364da2661108 | osvdb.org | |
| Hiki Session ID Arbitrary File Deletion Security Issue - Advisories - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | Patch, Vendor Advisory |
| JVN#05187780: Hiki において任意のファイルが削除可能な脆弱性 | af854a3a-2127-422b-91ae-364da2661108 | jvn.jp | |
| #430691 - hiki: [security] vulnerability that arbitrary files would be deleted - Debian Bug report logs | af854a3a-2127-422b-91ae-364da2661108 | bugs.debian.org | |
| IBM X-Force Exchange | af854a3a-2127-422b-91ae-364da2661108 | exchange.xforce.ibmcloud.com | |
| Debian -- Security Information -- DSA-1324-1 hiki | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Webmail : Solution de messagerie professionnelle - OVHcloud- OVH | af854a3a-2127-422b-91ae-364da2661108 | www.vupen.com | |
| Hiki - FrontPage | af854a3a-2127-422b-91ae-364da2661108 | hikiwiki.org | |
| JVN:JVN#05187780 | MITRE | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.