5
CVSSv2

CVE-2002-1079

Published: 04/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in Abyss Web Server 1.0.3 allows remote malicious users to read arbitrary files via ..\ (dot-dot backslash) sequences in an HTTP GET request.

Vulnerable Product Search on Vulmon Subscribe to Product

aprelium technologies abyss web server 1.0.3_p2

Exploits

source: wwwsecurityfocuscom/bid/5547/info A directory traversal vulnerability has been reported for Abyss Web Server The issue is related to the failure to properly process the backslash '\', encoded as '%5c', character, which may be used as a directory delimiter under these platforms By using the URL encoded sequence '%2e%2e%5c', the w ...