5
CVSSv2

CVE-2004-2464

Published: 31/12/2004 Updated: 07/11/2023
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in ADA Image Server (ImgSvr) 0.4 allows remote malicious users to read arbitrary files or list directories via hex-encoded "..//" sequences ("%2e%2e%2f%2f"). NOTE: it was later reported that 0.6.21 and previous versions is also affected.

Vulnerable Product Search on Vulmon Subscribe to Product

ada imgsvr 0.4

Exploits

source: wwwsecurityfocuscom/bid/10048/info ImgSvr is prone to an issue that may allow an attacker to view files that reside outside of the server root directory This issue occurs because the application fails to properly sanitize user-supplied URI data A successful exploit may allow a remote attacker to access sensitive information tha ...