5
CVSSv2

CVE-2002-0331

Published: 25/06/2002 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in the HTTP server for BPM Studio Pro 4.2 allows remote malicious users to read arbitrary files via a .. (dot dot) in the HTTP request.

Vulnerable Product Search on Vulmon Subscribe to Product

alcatech gmbh bpm studio pro 4.2

Exploits

source: wwwsecurityfocuscom/bid/4198/info BPM Studio Pro is a shareware MP3 mixer and player It runs on Microsoft Windows operating systems BPM Studio Pro includes a HTTP server for managing the player via a web interface The BPM Studio Pro HTTPD does not adequately filter dot-dot-slash (/) sequences from web requests As a result, ...