CVE-2008-0466

N/A Unknown
Published: January 29, 2008 Modified: April 23, 2026
View on NVD

Description

Web Wiz RTE_file_browser.asp in, as used in Web Wiz Rich Text Editor 4.0, Web Wiz Forums 9.07, and Web Wiz Newspad 1.02, does not require authentication, which allows remote attackers to list directories and read files. NOTE: this can be leveraged for listings outside the configured directory tree by exploiting a separate directory traversal vulnerability.

AI Explanation

Get an AI-powered plain-language explanation of this vulnerability and remediation steps.

Login to generate AI explanation

References to Advisories, Solutions, and Tools

Patch Vendor Advisory Exploit Third Party Advisory
http://www.bugreport.ir/?/29
Source: cve@mitre.org
http://www.bugreport.ir/?/31
Source: cve@mitre.org
http://securityreason.com/securityalert/3584
Source: af854a3a-2127-422b-91ae-364da2661108
http://securitytracker.com/id?1019267
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.bugreport.ir/?/29
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.bugreport.ir/?/31
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/486866/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/archive/1/486868/100/0/threaded
Source: af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/27419
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/4970
Source: af854a3a-2127-422b-91ae-364da2661108
https://www.exploit-db.com/exploits/4971
Source: af854a3a-2127-422b-91ae-364da2661108

20 reference(s) from NVD

Quick Stats

CVSS v3 Score
N/A / 10.0
EPSS (Exploit Probability)
4.9%
91th percentile
Exploitation Status
Not in CISA KEV

Weaknesses (CWE)

Affected Vendors

webwiz