CVE-2002-1837

The getAlbumToDisplay function in idsShared.pm for Image Display System (IDS) 0.81 allows remote attackers to determine the existence of arbitrary directories via ".." sequences in the album parameter, which generates different error messages depending on whether the directory exists or not.
Configurations

Configuration 1 (hide)

cpe:2.3:a:ids:ids:0.8.1:*:*:*:*:*:*:*

History

20 Nov 2024, 23:42

Type Values Removed Values Added
References () http://ids.sourceforge.net/ChangeLog.html - () http://ids.sourceforge.net/ChangeLog.html -
References () http://online.securityfocus.com/archive/1/274433 - () http://online.securityfocus.com/archive/1/274433 -
References () http://www.iss.net/security_center/static/9201.php - () http://www.iss.net/security_center/static/9201.php -
References () http://www.securityfocus.com/bid/4870 - Exploit () http://www.securityfocus.com/bid/4870 - Exploit

Information

Published : 2002-12-31 05:00

Updated : 2024-11-20 23:42


NVD link : CVE-2002-1837

Mitre link : CVE-2002-1837

CVE.ORG link : CVE-2002-1837


JSON object : View

Products Affected

ids

  • ids