CVE-2002-0196
N/A
N/A
Summary
GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.securityfocus.com/bid/3924
- http://www.iss.net/security_center/static/7981.php
- http://sourceforge.net/forum/forum.php?forum_id=144966
- http://online.securityfocus.com/archive/1/251699
References
- http://www.securityfocus.com/bid/3924
- http://www.iss.net/security_center/static/7981.php
- http://sourceforge.net/forum/forum.php?forum_id=144966
- http://online.securityfocus.com/archive/1/251699
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.