Vulnerabilities > CVE-2002-1982 - Directory Traversal Information Disclosure vulnerability in Icecast 1.3.12
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
NONE Availability impact
NONE Summary
Directory traversal vulnerability in the list_directory function in Icecast 1.3.12 allows remote attackers to determine if a directory exists via a .. (dot dot) in the GET request, which returns different error messages depending on whether the directory exists or not.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |
Exploit-Db
description | Icecast Server 1.3.12 Directory Traversal Information Disclosure Vulnerability. CVE-2002-1982. Remote exploit for linux platform |
id | EDB-ID:21602 |
last seen | 2016-02-02 |
modified | 2002-07-09 |
published | 2002-07-09 |
reporter | glaive |
source | https://www.exploit-db.com/download/21602/ |
title | icecast server 1.3.12 - Directory Traversal information disclosure Vulnerability |
Nessus
NASL family | CGI abuses |
NASL id | ICECAST_DISCLOSURE.NASL |
description | The remote server does not return the same error codes when it is requested a nonexistent directory and an existing one. An attacker may use this flaw to deduct the presence of several key directory on the remote server, and therefore gain further knowledge about it. |
last seen | 2020-06-01 |
modified | 2020-06-02 |
plugin id | 11044 |
published | 2002-07-10 |
reporter | This script is Copyright (C) 2002-2018 Tenable Network Security, Inc. |
source | https://www.tenable.com/plugins/nessus/11044 |
title | Icecast list_directory Function Traversal File/Directory Enumeration |
code |
|