CVE Vulnerabilities

CVE-2000-1048

Published: Dec 11, 2000 | Modified: Dec 19, 2017
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GET request that uses encoded characters in the URL.

Affected Software

Name Vendor Start Version End Version
Wingate Qbik 2.1 2.1
Wingate Qbik 3.0 3.0
Wingate Qbik 4.0.1 4.0.1
Wingate Qbik 4.1_beta_a 4.1_beta_a

References