Início
Tendências
Vulnerabilidades
Notícias
Pesquisadores
Por que dbugs?

Derek Price

#48810de 53,639
5CVSS total
Vulnerabilidades · 1
PT-2004-1090
5.0
2004-04-14
Cvs · Cvs · CVE-2004-0405
**Name of the Vulnerable Software and Affected Versions** CVS versions prior to 1.11.14 **Description** The issue allows attackers to read arbitrary files via .. (dot dot) sequences in filenames via CVS client requests. This can lead to a breach of confidentiality of protected information. Exploitation of the issue can be done remotely. **Recommendations** For versions prior to 1.11.14, update to version 1.11.14 or later to resolve the issue. As a temporary workaround, consider restricting access to the CVS client requests to minimize the risk of exploitation.