5
CVSSv2

CVE-2002-1982

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote malicious users to determine if a directory exists via a .. (dot dot) in the GET request, which returns different error messages depending on whether the directory exists or not.

Vulnerable Product Search on Vulmon Subscribe to Product

icecast icecast 1.3.12

Exploits

source: wwwsecurityfocuscom/bid/5189/info Icecast is a freely available, open source streaming audio server Icecast is available for the Unix, Linux, and Microsoft Windows platforms An attacker may exploit a directory traversal vulnerability in Icecast server to determine the existance of a specified directory outside of the web root ...