CVE Vulnerabilities

CVE-2002-1483

Published: Apr 22, 2003 | Modified: Sep 05, 2008
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
5 MEDIUM
AV:N/AC:L/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

db4web_c and db4web_c.exe programs in DB4Web 3.4 and 3.6 allow remote attackers to read arbitrary files via an HTTP request whose argument is a filename of the form (1) C: (drive letter), (2) //absolute/path (double-slash), or (3) .. (dot-dot).

Affected Software

Name Vendor Start Version End Version
Db4web Db4web 3.4 (including) 3.4 (including)
Db4web Db4web 3.6 (including) 3.6 (including)

References