5
CVSSv2

CVE-2002-1224

Published: 28/10/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in kpf for KDE 3.0.1 through KDE 3.0.3a allows remote malicious users to read arbitrary files as the kpf user via a URL with a modified icon parameter.

Vulnerable Product Search on Vulmon Subscribe to Product

kde kde 3.0.1

kde kde 3.0.3

kde kde 3.0.2

kde kde 3.0.3a

Exploits

source: wwwsecurityfocuscom/bid/5951/info A vulnerability has been discovered in the kpf file sharing utility KDE is available for the Linux operating system It has been reported that by passing a malicious file request to kpf, it is possible for a remote attacker to access files outside of the 'shared directory' root The ability to r ...