PT-2002-2133 · Dino · Dino'S Webserver
Published
2002-09-24
·
Updated
2016-10-18
·
CVE-2002-1133
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Dino's web server version 2.1
Description:
The issue allows remote attackers to read arbitrary files via ".." (dot dot) sequences with URL-encoded (1) "/" (%2f) or (2) "" (%5c) characters. This is an encoded directory traversal vulnerability.
Recommendations:
For version 2.1, update to a version that fixes the directory traversal issue to prevent remote attackers from reading arbitrary files.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Dino'S Webserver