5
CVSSv2

CVE-2013-4900

Published: 09/09/2013 Updated: 13/09/2013
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 510
Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N

Vulnerability Summary

Directory traversal vulnerability in DeWeS web server 0.4.2 and possibly earlier, as used in Twilight CMS, allows remote malicious users to read arbitrary files via a ..%5c (dot dot encoded backslash) in a GET request.

Vulnerable Product Search on Vulmon Subscribe to Product

twilightcms twilight cms 5.17

Exploits

DeWeS web server version 042 suffers from a path traversal vulnerability ...
Advisory ID: HTB23167 Product: DeWeS web server (Twilight CMS) Vendor: Strata Technologies LLC Vulnerable Version(s): 042 and probably prior Tested Version: 042 Vendor Notification: July 24, 2013 Public Disclosure: August 21, 2013 Vulnerability Type: Path Traversal [CWE-22] CVE Reference: CVE-2013-4900 Risk Level: Medium CVSSv2 Base Score: ...
source: wwwsecurityfocuscom/bid/61906/info Twilight CMS is prone to a directory-traversal vulnerability because it fails to properly sanitize user-supplied input Remote attackers can use specially crafted requests with directory-traversal sequences ('/') to retrieve arbitrary files in the context of the application Exploiting this i ...