VulnerabilityModified
CVE-2004-1715
Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 allows remote attackers or local users to read arbitrary files via "..\\", "..\", and similar dot dot sequences in the URL.
MEDIUM 5.0EPSS 2.04%
Does this matter?
Lower severity and a low EPSS score (2.04%). Track it; it rarely justifies an emergency change on its own.
Description
Directory traversal vulnerability in MIMEsweeper for Web before 5.0.4 allows remote attackers or local users to read arbitrary files via "..\\", "..\", and similar dot dot sequences in the URL.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 2.04% probability · 80th percentile
- CISA KEV
- Not listed
- Affected
- clearswift/mimesweeper for web
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=109224211512029&w=2
- http://marc.info/?l=bugtraq&m=109225567212978&w=2
- http://packetstormsecurity.nl/0408-exploits/clearswift.txtExploit, Vendor Advisory
- http://secunia.com/advisories/12273Vendor Advisory
- http://www.securityfocus.com/bid/10918Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16960
- http://marc.info/?l=bugtraq&m=109224211512029&w=2
- http://marc.info/?l=bugtraq&m=109225567212978&w=2
- http://packetstormsecurity.nl/0408-exploits/clearswift.txtExploit, Vendor Advisory
- http://secunia.com/advisories/12273Vendor Advisory
- http://www.securityfocus.com/bid/10918Exploit, Patch, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/16960
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.