5
CVSSv2

CVE-2000-0904

Published: 19/12/2000 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Voyager web server 2.01B in the demo disks for QNX 405 stores sensitive web client information in the .photon directory in the web document root, which allows remote malicious users to obtain that information.

Vulnerable Product Search on Vulmon Subscribe to Product

qnx voyager 2.01b

Exploits

source: wwwsecurityfocuscom/bid/1648/info The web server supplied with the QNX Voyager demo disk contains several vulnerabilities First, Voyager will follow relative paths passed to it in requests This includes / style paths, which will allow Voyager to serve pages outside of the "document root" Another vulnerability is that the w ...