5
CVSSv2

CVE-2003-0338

Published: 21/05/2003 Updated: 18/10/2016
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in WsMp3 daemon (WsMp3d) 0.0.10 and previous versions allows remote malicious users to read and execute arbitrary files via .. (dot dot) sequences in HTTP GET or POST requests.

Vulnerable Product Search on Vulmon Subscribe to Product

wsmp3 wsmp3 daemon 0.0.8

wsmp3 wsmp3 daemon 0.0.9

wsmp3 wsmp3 web server 0.0.7

wsmp3 wsmp3 daemon 0.0.10

wsmp3 wsmp3 web server 0.0.5

wsmp3 wsmp3 web server 0.0.6

wsmp3 wsmp3 web server 0.0.3

wsmp3 wsmp3 web server 0.0.4

wsmp3 wsmp3 web server 0.0.1

wsmp3 wsmp3 web server 0.0.2

Exploits

source: wwwsecurityfocuscom/bid/7645/info A vulnerability has been reported in WsMp3 The problem occurs due to insufficient sanitization of HTTP POST requests As a result, an attacker may be capable of executing arbitrary files on a target system This may lead to the complete compromise of a target system bash$ telnet wsmp3serverc ...