Pico Server (pServ) 3.2 and earlier allows remote attackers to execute arbitrary commands via a URL with multiple leading "/" (slash) characters and ".." sequences.
References
Configurations
Configuration 1 (hide)
|
History
20 Nov 2024, 23:57
Type | Values Removed | Values Added |
---|---|---|
References | () http://marc.info/?l=full-disclosure&m=111625635716712&w=2 - | |
References | () http://sourceforge.net/project/shownotes.php?release_id=327708 - | |
References | () http://www.redteam-pentesting.de/advisories/rt-sa-2005-010.txt - Exploit, Vendor Advisory | |
References | () http://www.securityfocus.com/bid/13642 - |
Information
Published : 2005-05-16 04:00
Updated : 2024-11-20 23:57
NVD link : CVE-2005-1365
Mitre link : CVE-2005-1365
CVE.ORG link : CVE-2005-1365
JSON object : View
Products Affected
pico_server
- pico_server
CWE