CVE-2003-1298
Multiple directory traversal vulnerabilities in siteman.php3 in AnyPortal(php) 12 MAY 00 allow remote attackers to (1) create, (2) delete, (3) save, and (4) upload files by navigating to the root directory and entering a filename beginning with "./.."…
Does this matter?
Lower severity and a low EPSS score (1.95%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple directory traversal vulnerabilities in siteman.php3 in AnyPortal(php) 12 MAY 00 allow remote attackers to (1) create, (2) delete, (3) save, and (4) upload files by navigating to the root directory and entering a filename beginning with "./.." (dot slash dot dot).
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 1.95% probability · 79th percentile
- CISA KEV
- Not listed
- Affected
- anyportal php/anyportal php
- Source
- cve@mitre.org
References
- http://nger.org/anyportal/forum/read.php?f=1&i=152&t=152#reply_152Exploit
- http://secunia.com/advisories/19359Vendor Advisory
- http://www.osvdb.org/23984Exploit
- http://www.securityfocus.com/bid/17197
- http://www.vupen.com/english/advisories/2006/1053
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25396
- http://nger.org/anyportal/forum/read.php?f=1&i=152&t=152#reply_152Exploit
- http://secunia.com/advisories/19359Vendor Advisory
- http://www.osvdb.org/23984Exploit
- http://www.securityfocus.com/bid/17197
- http://www.vupen.com/english/advisories/2006/1053
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25396
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.