5
CVSSv2

CVE-2002-1525

Published: 02/04/2003 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote malicious users to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (3) an absolute pathname to port 6017.

Vulnerable Product Search on Vulmon Subscribe to Product

sun sunone starter kit 2.0

astaware searchdisc 3.1

Exploits

source: wwwsecurityfocuscom/bid/5828/info A vulnerability has been reported for the Sun ONE Starter Kit 20 and ASTAware SearchDisc The Starter Kit includes a search engine facility provided for easy information retrieval The search engine included with the Starter Kit is a modified version of ASTAWare SearchDisc Reportedly, the search ...