Vulnerability Name: | CVE-2003-1413 (CCN-11445) | ||||||||
Assigned: | 2003-02-28 | ||||||||
Published: | 2003-02-28 | ||||||||
Updated: | 2017-07-29 | ||||||||
Summary: | parse_xml.cgi in Apple Darwin Streaming Server 4.1.1 allows remote attackers to determine the existence of arbitrary files by using ".." sequences in the filename parameter and comparing the resulting error messages. | ||||||||
CVSS v3 Severity: | 5.3 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
| ||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:N/I:N/A:P)
| ||||||||
Vulnerability Type: | CWE-22 | ||||||||
Vulnerability Consequences: | Obtain Information | ||||||||
References: | Source: CCN Type: BugTraq Mailing List, Fri Feb 28 2003 - 13:21:35 CST Re: QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities Source: MITRE Type: CNA CVE-2003-1413 Source: CCN Type: Apple Computer, Inc. Web site Apple - Public Source - Darwin Streaming Server Source: SREASON Type: UNKNOWN 3260 Source: CCN Type: OSVDB ID: 60286 Apple Darwin Streaming Server parse_xml.cgi Traversal Error Message File Enumeration Source: BUGTRAQ Type: UNKNOWN 20030228 Re: QuickTime/Darwin Streaming Administration Server Multiple vulnerabilities Source: BID Type: Exploit 6992 Source: CCN Type: BID-6992 Apple QuickTime/Darwin Streaming Server Remote File Existence Revealing Vulnerability Source: XF Type: UNKNOWN darwin-dotdot-file-existence(11445) Source: XF Type: UNKNOWN darwin-dotdot-file-existence(11445) | ||||||||
Vulnerable Configuration: | Configuration 1: Denotes that component is vulnerable | ||||||||
BACK |