5
CVSSv2

CVE-2004-2617

Published: 31/12/2004 Updated: 20/07/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote malicious users to read files outside of the web root via a .. (dot dot) directly after the initial '/' (slash) in the URI.

Vulnerable Product Search on Vulmon Subscribe to Product

pegasi web server pegasi web server 0.2.2

Exploits

source: wwwsecurityfocuscom/bid/9847/info Multiple vulnerabilities have been identified in the application that may allow a remote attacker to carry out directory traversal and cross-site scripting attacks A successful cross-site scripting attack may make it possible for an attacker to create a malicious link to a vulnerable site that in ...