Vulnerability Name: | CVE-2002-2375 (CCN-9463) | ||||||||
Assigned: | 2002-07-02 | ||||||||
Published: | 2002-07-02 | ||||||||
Updated: | 2008-09-05 | ||||||||
Summary: | Directory traversal vulnerability in CommuniGate Pro 4.0b4 and possibly earlier versions allows remote attackers to list the contents of the WebUser directory and its parent directory via a (1) .. (dot dot) or (2) . (dot) in a URL. Note: it is not clear whether this issue reveals any more information regarding directory structure than is already available to any CommuniGate Pro user, although there is a possibility that it could be used to infer product version information. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 5.0 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:N)
| ||||||||
Vulnerability Type: | CWE-22 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: BUGTRAQ Type: UNKNOWN 20020702 CommuniGate Pro directory listings Source: CCN Type: BugTraq Mailing List, Tue Jul 02 2002 - 00:56:02 CDT CommuniGate Pro directory listings Source: MITRE Type: CNA CVE-2002-2375 Source: XF Type: UNKNOWN communigatepro-view-dir-listings(9463) Source: CCN Type: OSVDB ID: 59525 CommuniGate Pro URI Traversal Limited Directory Tree Listing Source: CCN Type: Stalker Software Web site CommuniGate Pro: Introduction Source: XF Type: UNKNOWN communigatepro-view-dir-listings(9463) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |