Vulnerabilities > CVE-2004-0072 - Remote File Disclosure vulnerability in Accipiter Direct Server 6.0

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
accipiter
exploit available

Summary

Directory traversal vulnerability in Accipiter Direct Server 6.0 allows remote attackers to read arbitrary files via encoded \.. (backslash .., "%5c%2e%2e") sequences in an HTTP request.

Vulnerable Configurations

Part Description Count
Application
Accipiter
1

Exploit-Db

descriptionAccipiter DirectServer 6.0 Remote File Disclosure Vulnerability. CVE-2004-0072. Remote exploit for windows platform
idEDB-ID:23533
last seen2016-02-02
modified2004-01-09
published2004-01-09
reporterMark Bassett
sourcehttps://www.exploit-db.com/download/23533/
titleAccipiter DirectServer 6.0 - Remote File Disclosure Vulnerability