5
CVSSv2

CVE-1999-1082

Published: 08/10/1999 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in Jana proxy web server 1.40 allows remote malicious users to ready arbitrary files via a "......" (modified dot dot) attack.

Vulnerable Product Search on Vulmon Subscribe to Product

t. hauck jana web server 1.0

t. hauck jana web server 1.40

t. hauck jana web server 1.45

t. hauck jana web server 1.46

Exploits

source: wwwsecurityfocuscom/bid/699/info The Jana webserver is susceptible to directory traversal attacks using multiple dots in the URL If the request is made in specific formats, the server will send out files outside of the intended webroot http ://target////////winini or http ://target//autoexe ...