Vulnerabilities > CVE-2004-2121 - Directory Traversal vulnerability in Borland Webserver for Corel Paradox

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
borland-software
exploit available

Summary

Multiple directory traversal vulnerabilities in Borland Web Server (BWS) 1.0b3 and earlier allow remote attackers to read and download arbitrary files via (1) multi-dot "......" sequences, or (2) "%5c%2e%2e" (encoded "\..") sequences, in the URL.

Vulnerable Configurations

Part Description Count
Application
Borland_Software
1

Exploit-Db

descriptionBorland Web Server for Corel Paradox 1.0 b3 Directory Traversal Vulnerability. CVE-2004-2121. Remote exploit for windows platform
idEDB-ID:23597
last seen2016-02-02
modified2004-01-24
published2004-01-24
reporterRafel Ivgi The-Insider
sourcehttps://www.exploit-db.com/download/23597/
titleborland Web server for corel paradox 1.0 b3 - Directory Traversal Vulnerability