CWE-59
Medium likelihoodImproper Link Resolution Before File Access ('Link Following')
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
1,527 vulnerabilities with CWE-59
CVE-2008-6760
ViArt Shop 3.5 - Unauthenticated Sensitive Information Exposure via Cart Save Action
CVE-2008-6759
ViArt Shop 3.5 - Information Disclosure via POST_DATA Parameter
CVE-2008-6552
Red Hat Cluster Project 2.x - Arbitrary File Write via Symlink Attack in /tmp
CVE-2008-6398
SNG 1.0.2 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2008-6397
sgml2x 1.0.0 - Arbitrary File Overwrite via Symlink Attack on Temporary Files
CVE-2008-4284
IBM WebSphere Application Server Open Redirect via ibm_security_logout Servlet
CVE-2008-4990
Enomaly Elastic Computing Platform < 2.1.1 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2008-5825
Nokia 6131 NFC - URI Spoofing via Crafted NDEF Tag
CVE-2008-5746
Sun SNMP Management Agent - Privilege Escalation
CVE-2008-5743
pdfjam - Arbitrary File Overwrite via Symlink Attack
CVE-2008-5742
AIST NetCat <= 3.12 - Open Redirect via Logoff or Link Manager
CVE-2008-5706
Verlihub <0.9.8d-RC2 - Local File Overwrite
CVE-2008-5704
gpsdrive <2.10~pre4 - Local Privilege Escalation
CVE-2008-5703
gpsdrive 2.10~pre4 - Local File Overwrite
CVE-2008-5394
Debian GNU/Linux - Local Privilege Escalation
CVE-2008-5380
gpsdrive 2.09 - Local Privilege Escalation
CVE-2008-5379
netdisco-mibs-installer 1.0 - Local File Overwrite
CVE-2008-5378
arb 0.0.20071207.1 - Local Privilege Escalation
CVE-2008-5377
CUPS 1.3.8 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2008-5376
crip 3.7 - Arbitrary File Overwrite via Symlink Attack on Temporary File
CVE-2008-5375
cmus <2.2.0 - Local Privilege Escalation
CVE-2008-5374
bash-doc <3.2 - Local File Overwrite
CVE-2008-5373
mtx-changer.Adic-Scalar-24 - Local Privilege Escalation
CVE-2008-5372
sdm-terminal 0.4.0b - Local Privilege Escalation
CVE-2008-5371
Screenie <1.30.0 - Local Privilege Escalation
Details
Vulnerabilities
1,527
Exploit Likelihood
Medium