5

CVE-2004-2565

Exploit
Multiple directory traversal vulnerabilities in Sambar Server 6.1 Beta 2 on Windows, and possibly other versions on Linux, when the administrative IP address restrictions have been modified from the default, allow remote authenticated users to read arbitrary files via (1) a "..\" (dot dot backslash) in the file parameter to showini.asp, or (2) an absolute path with drive letter in the log parameter to showlog.asp.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
SambarSambar Server Version6.1 Updatebeta2
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 9.37% 0.948
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 5 10 2.9
AV:N/AC:L/Au:N/C:P/I:N/A:N
Es wurden noch keine Informationen zu CWE veröffentlicht.
http://secunia.com/advisories/11748
Vendor Advisory
Exploit
http://securitytracker.com/id?1010353
Exploit
http://www.oliverkarow.de/research/sambar.txt
Exploit
http://www.securityfocus.com/bid/10444
Exploit
http://www.osvdb.org/6585
Exploit
https://exchange.xforce.ibmcloud.com/vulnerabilities/16287