{"api_version":"1","generated_at":"2026-07-23T05:03:11+00:00","cve":"CVE-2007-4655","urls":{"html":"https://cve.report/CVE-2007-4655","api":"https://cve.report/api/cve/CVE-2007-4655.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2007-4655","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2007-4655"},"summary":{"title":"CVE-2007-4655","description":"Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal sequences in unspecified parameters to (1) list.cgi or (2) list2.cgi.","state":"PUBLISHED","assigner":"mitre","published_at":"2007-09-04 22:17:00","updated_at":"2026-04-23 00:35:47"},"problem_types":["CWE-22","CWE-200","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"5","severity":"","vector":"AV:N/AC:L/Au:N/C:P/I:N/A:N","data":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"}}],"references":[{"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36389","name":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36389","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"IBM X-Force Exchange","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://osvdb.org/40146","name":"http://osvdb.org/40146","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://osvdb.org/40147","name":"http://osvdb.org/40147","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"","mime":"","httpstatus":"-1","archivestatus":"0"},{"url":"http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20070823212803","name":"http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20070823212803","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"ブログ: ショッピングバスケットプロｖ７ ..","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/25500","name":"http://www.securityfocus.com/bid/25500","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"Shopping Cart Professional Unspecified Multiple Directory Traversal Vulnerabilities","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://secunia.com/advisories/26614","name":"http://secunia.com/advisories/26614","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"About Secunia Research | Flexera","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://jvn.jp/jp/JVN%2320452446/index.html","name":"http://jvn.jp/jp/JVN%2320452446/index.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"JVN#20452446: ショッピングバスケットプロにおけるディレクトリトラバーサルの脆弱性","mime":"text/xml","httpstatus":"200","archivestatus":"404"},{"url":"http://jvn.jp/jp/JVN#20452446/index.html","name":"JVN:JVN#20452446","refsource":"MITRE","tags":[],"title":"","mime":"text/plain","httpstatus":"404","archivestatus":"404"},{"url":"https://www.cve.org/CVERecord?id=CVE-2007-4655","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2007-4655","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2007","cve_id":"4655","vulnerable":"1","versionEndIncluding":"7.51","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cgi-rescue","cpe5":"shopping_basket_professional","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-07T15:01:09.916Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20070823212803"},{"name":"40147","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/40147"},{"name":"JVN#20452446","tags":["third-party-advisory","x_refsource_JVN","x_transferred"],"url":"http://jvn.jp/jp/JVN%2320452446/index.html"},{"name":"shoppingbasketpro-information-disclosure(36389)","tags":["vdb-entry","x_refsource_XF","x_transferred"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36389"},{"name":"40146","tags":["vdb-entry","x_refsource_OSVDB","x_transferred"],"url":"http://osvdb.org/40146"},{"name":"26614","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/26614"},{"name":"25500","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/25500"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2007-08-31T00:00:00.000Z","descriptions":[{"lang":"en","value":"Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal sequences in unspecified parameters to (1) list.cgi or (2) list2.cgi."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-07-28T12:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"tags":["x_refsource_MISC"],"url":"http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20070823212803"},{"name":"40147","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/40147"},{"name":"JVN#20452446","tags":["third-party-advisory","x_refsource_JVN"],"url":"http://jvn.jp/jp/JVN%2320452446/index.html"},{"name":"shoppingbasketpro-information-disclosure(36389)","tags":["vdb-entry","x_refsource_XF"],"url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36389"},{"name":"40146","tags":["vdb-entry","x_refsource_OSVDB"],"url":"http://osvdb.org/40146"},{"name":"26614","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/26614"},{"name":"25500","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/25500"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2007-4655","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal sequences in unspecified parameters to (1) list.cgi or (2) list2.cgi."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20070823212803","refsource":"MISC","url":"http://www.rescue.ne.jp/whatsnew/blog.cgi/permalink/20070823212803"},{"name":"40147","refsource":"OSVDB","url":"http://osvdb.org/40147"},{"name":"JVN#20452446","refsource":"JVN","url":"http://jvn.jp/jp/JVN%2320452446/index.html"},{"name":"shoppingbasketpro-information-disclosure(36389)","refsource":"XF","url":"https://exchange.xforce.ibmcloud.com/vulnerabilities/36389"},{"name":"40146","refsource":"OSVDB","url":"http://osvdb.org/40146"},{"name":"26614","refsource":"SECUNIA","url":"http://secunia.com/advisories/26614"},{"name":"25500","refsource":"BID","url":"http://www.securityfocus.com/bid/25500"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2007-4655","datePublished":"2007-09-04T22:00:00.000Z","dateReserved":"2007-09-04T00:00:00.000Z","dateUpdated":"2024-08-07T15:01:09.916Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2007-09-04 22:17:00","lastModifiedDate":"2026-04-23 00:35:47","problem_types":["CWE-22","CWE-200","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:N/AC:L/Au:N/C:P/I:N/A:N","baseScore":5,"accessVector":"NETWORK","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"PARTIAL","integrityImpact":"NONE","availabilityImpact":"NONE"},"baseSeverity":"MEDIUM","exploitabilityScore":10,"impactScore":2.9,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cgi-rescue:shopping_basket_professional:*:*:*:*:*:*:*:*","versionEndIncluding":"7.51","matchCriteriaId":"647E8A28-D94A-4A6E-BA90-CBE83FF74CFC"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2007","CveId":"4655","Ordinal":"1","Title":"CVE-2007-4655","CVE":"CVE-2007-4655","Year":"2007"},"notes":[{"CveYear":"2007","CveId":"4655","Ordinal":"1","NoteData":"Multiple directory traversal vulnerabilities in CGI RESCUE Shopping Basket Professional 7.51 and earlier allow remote attackers to list arbitrary directories, and possibly read arbitrary files, via directory traversal sequences in unspecified parameters to (1) list.cgi or (2) list2.cgi.","Type":"Description","Title":"CVE-2007-4655"},{"CveYear":"2007","CveId":"4655","Ordinal":"2","NoteData":"2007-09-04","Type":"Other","Title":"Published"},{"CveYear":"2007","CveId":"4655","Ordinal":"3","NoteData":"2017-07-28","Type":"Other","Title":"Modified"}]}}}