5
CVSSv2

CVE-2004-2253

Published: 31/12/2004 Updated: 11/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in user.cgi in SurgeLDAP 1.0g and previous versions allows remote malicious users to read arbitrary files via a .. in the page parameter of the show command.

Vulnerable Product Search on Vulmon Subscribe to Product

netwin surgeldap 1.0d

netwin surgeldap 1.0e

netwin surgeldap 1.0g

Exploits

source: wwwsecurityfocuscom/bid/10103/info SurgeLDAP is prone to a directory traversal vulnerability in one of the scripts included with the built-in web administrative server, potentially resulting in disclosure of files A remote attacker could exploit this issue to gain access to system files outside of the web root directory of the ...