Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote attackers to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.
References
Configurations
History
20 Nov 2024, 23:43
Type | Values Removed | Values Added |
---|---|---|
References | () http://archives.neohapsis.com/archives/vulnwatch/2002-q4/0073.html - Exploit | |
References | () http://securityreason.com/securityalert/3331 - Exploit | |
References | () http://www.iss.net/security_center/static/10622.php - | |
References | () http://www.keyfocus.net/kfws/support/ - | |
References | () http://www.securityfocus.com/archive/1/299742 - Exploit | |
References | () http://www.securityfocus.com/bid/6180 - Exploit |
Information
Published : 2002-12-31 05:00
Updated : 2024-11-20 23:43
NVD link : CVE-2002-2403
Mitre link : CVE-2002-2403
CVE.ORG link : CVE-2002-2403
JSON object : View
Products Affected
key_focus
- kf_web_server
CWE
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')