Vulnerabilities > CVE-2004-2516 - Directory Traversal vulnerability in MyServer

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
myserver
nessus
exploit available

Summary

Directory traversal vulnerability in myServer 0.7 allows remote attackers to list arbitrary directories via an HTTP GET command with a large number of "./" sequences followed by "../" sequences.

Vulnerable Configurations

Part Description Count
Application
Myserver
1

Exploit-Db

descriptionMyServer 0.7 Directory Traversal Vulnerability. CVE-2004-2516. Remote exploit for windows platform
idEDB-ID:24600
last seen2016-02-02
modified2004-09-15
published2004-09-15
reporterscrap
sourcehttps://www.exploit-db.com/download/24600/
titlemyserver 0.7 - Directory Traversal Vulnerability

Nessus

NASL familyWeb Servers
NASL idMYSERVER_TRAVERSAL.NASL
descriptionThis web server is running MyServer <= 0.4.3 or 0.7. This version contains a directory traversal vulnerability, that allows remote users with no authentication to read files outside the webroot. You have to create a dot-dot URL with the same number of
last seen2020-06-01
modified2020-06-02
plugin id11851
published2003-09-26
reporterAuthor Paul Johnston [email protected], Copyright (C) 2003-2018 Westpoint Ltd
sourcehttps://www.tenable.com/plugins/nessus/11851
titleMyServer 0.4.3 / 0.7 Crafted Traversal Arbitrary File Access