5
CVSSv2

CVE-2002-2416

Published: 31/12/2002 Updated: 05/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:N/I:P/A:N

Vulnerability Summary

Directory traversal vulnerability in Zeroo web server 1.5 allows remote malicious users to read arbitrary files via a .. (dot dot) in a URL GET request.

Vulnerable Product Search on Vulmon Subscribe to Product

zeroo http server 1.5

Exploits

source: wwwsecurityfocuscom/bid/6308/info It has been reported that Zeroo fails to properly sanitize web requests By sending a malicious web request to the vulnerable server, using directory traversal sequences, it is possible for a remote attacker to access sensitive resources located outside of the web root An attacker is able to tra ...
source: wwwsecurityfocuscom/bid/6308/info It has been reported that Zeroo fails to properly sanitize web requests By sending a malicious web request to the vulnerable server, using directory traversal sequences, it is possible for a remote attacker to access sensitive resources located outside of the web root An attacker is able to t ...