5
CVSSv2

CVE-2001-0804

Published: 06/12/2001 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in story.pl in Interactive Story 1.3 allows a remote malicious user to read arbitrary files via a .. (dot dot) attack on the "next" parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

valerie mates interactive story 1.3

Exploits

source: wwwsecurityfocuscom/bid/3028/info Interactive Story is a web-based application written in Perl and is distributed as freeware Interactive Story does not filter '/' sequences from user input submitted to a hidden file called 'next' Remote attackers may take advantage of this by crafting URLs that allow them to break out of web ...