Vulnerabilities > CVE-2004-2640 - Remote Directory Traversal vulnerability in LinuxStat

047910
CVSS 5.0 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
NONE
network
low complexity
ryszard-pydo
exploit available

Summary

Directory traversal vulnerability in lstat.cgi in LinuxStat before 2.3.1 allows remote attackers to read arbitrary files via (1) .. (dot dot) sequences or (2) absolute paths to the template parameter.

Exploit-Db

descriptionLinuxStat 2.x Remote Directory Traversal Vulnerability. CVE-2004-2640. Webapps exploit for cgi platform
idEDB-ID:24703
last seen2016-02-02
modified2004-10-25
published2004-10-25
reporteranonymous
sourcehttps://www.exploit-db.com/download/24703/
titleLinuxStat 2.x - Remote Directory Traversal Vulnerability