PT-2003-2124 · Apache · Apache Cocoon

Published

2003-12-31

·

Updated

2017-07-11

·

CVE-2003-1172

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Apache Software Foundation Cocoon versions 2.1 through 2.2
Description The issue allows remote attackers to access arbitrary files via a .. (dot dot) in the filename parameter. This is a directory traversal vulnerability in the view-source sample file.
Recommendations For Apache Software Foundation Cocoon versions 2.1 through 2.2, consider restricting access to the view-source sample file until a patch is available. Avoid using the filename parameter with untrusted input in the affected API endpoint until the issue is resolved.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2003-1172

Affected Products

Apache Cocoon