Vulnerabilities > CVE-2004-2617 - Input Validation vulnerability in Pegasi web Server Pegasi web Server 0.2.2

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
pegasi-web-server
exploit available

Summary

Directory traversal vulnerability in Pegasi Web Server (PWS) 0.2.2 allows remote attackers to read files outside of the web root via a .. (dot dot) directly after the initial '/' (slash) in the URI.

Vulnerable Configurations

Part Description Count
Application
Pegasi_Web_Server
1

Exploit-Db

descriptionPegasi Web Server 0.2.2 Arbitrary File Access. CVE-2004-2617. Remote exploit for linux platform
idEDB-ID:23802
last seen2016-02-02
modified2004-03-11
published2004-03-11
reporterDonato Ferrante
sourcehttps://www.exploit-db.com/download/23802/
titlePegasi Web Server 0.2.2 - Arbitrary File Access