Vulnerabilities
Vulnerable Software

Vulnerability Details CVE-2008-4297

Mercurial before 1.0.2 does not enforce the allowpull permission setting for a pull operation from hgweb, which allows remote attackers to read arbitrary files from a repository via an "hg pull" request.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.008
EPSS Ranking 72.2%
CVSS Severity
CVSS v2 Score 5.0
References
Products affected by CVE-2008-4297


Contact Us

Shodan ® - All rights reserved