CVE Vulnerabilities

CVE-2000-1048

Published: Dec 11, 2000 | Modified: Apr 03, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
root.io minimus.io echohq.com

Directory traversal vulnerability in the logfile service of Wingate 4.1 Beta A and earlier allows remote attackers to read arbitrary files via a .. (dot dot) attack via an HTTP GET request that uses encoded characters in the URL.

Affected Software

Name Vendor Start Version End Version
Wingate Qbik 2.1 (including) 2.1 (including)
Wingate Qbik 3.0 (including) 3.0 (including)
Wingate Qbik 4.0.1 (including) 4.0.1 (including)
Wingate Qbik 4.1_beta_a (including) 4.1_beta_a (including)

References