PT-2003-2124 · Apache · Apache Cocoon
Published
2003-12-31
·
Updated
2017-07-11
·
CVE-2003-1172
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Apache Software Foundation Cocoon versions 2.1 through 2.2
Description
The issue allows remote attackers to access arbitrary files via a .. (dot dot) in the
filename parameter. This is a directory traversal vulnerability in the view-source sample file.Recommendations
For Apache Software Foundation Cocoon versions 2.1 through 2.2, consider restricting access to the view-source sample file until a patch is available. Avoid using the
filename parameter with untrusted input in the affected API endpoint until the issue is resolved.Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Apache Cocoon