CVE-2013-7448 describes a directory traversal vulnerability in didiwiki's wiki.c, specifically affecting Debian Linux and didiwiki projects. This flaw allows remote attackers to read arbitrary files by manipulating the 'page' parameter in requests to api/page/get. With a CVSS score of 7.5 (HIGH), it presents a significant risk due to its low attack complexity and high impact on confidentiality, requiring no user interaction. There is currently no evidence of active exploitation, and no public exploit code or significant community discussion has been identified.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
7.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:* | ||
8.0CPE matchmatch criteria | cpe:2.3:o:debian:debian_linux:8.0:*:*:*:*:*:*:* | ||
All Versions ImpactedCPE matchmatch criteria | cpe:2.3:a:didiwiki_project:didiwiki:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.