5
CVSSv2

CVE-2003-0802

Published: 06/10/2003 Updated: 10/09/2008
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Nokia Electronic Documentation (NED) 5.0 allows remote malicious users to obtain a directory listing of the WebLogic web root, and the physical path of the NED server, via a "retrieve" action with a location parameter of . (dot).

Vulnerable Product Search on Vulmon Subscribe to Product

nokia electronic documentation 5.0

Exploits

source: wwwsecurityfocuscom/bid/8624/info Nokia Electronic Documentation (NED) is prone to a vulnerability that may enable remote attackers to list directory contents This issue may be exploited by appending a dot () to a request for a NED page Exploitation will also have the side-effect of disclosing the path to the directory This i ...