5
CVSSv2

CVE-2002-2403

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in KeyFocus web server 1.0.8 allows remote malicious users to read arbitrary files for recognized MIME type files via "...", "....", ".....", and other multiple dot sequences.

Vulnerable Product Search on Vulmon Subscribe to Product

key focus kf web server 1.0.8

Exploits

source: wwwsecurityfocuscom/bid/6180/info KeyFocus KF Web Server is vulnerable to a directory traversal attack This is due to the web server's inability to properly handle file names containing consecutive dot characters By exploiting this vulnerability, an attacker is able to break out of the web root and retrieve any file readable by ...