5
CVSSv2

CVE-2002-0908

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the web server for Cisco IDS Device Manager prior to 3.1.2 allows remote malicious users to read arbitrary files via a .. (dot dot) in the HTTPS request.

Vulnerable Product Search on Vulmon Subscribe to Product

cisco ids device manager 3.1.1

Exploits

source: wwwsecurityfocuscom/bid/4760/info IDS Device Manager is a web interface to the Cisco IDS systems It is distributed and maintained by Cisco Systems The IDS Device Manager may allow a remote user to gain access to sensitive information on the system Due to improper handling of user-supplied input, it is possible for a user to ga ...