VulnerabilityModified
CVE-2004-1857
Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a ..
LOW 2.1EPSS 86.8%
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 86.8%, higher than 100% of all known CVEs. Patch or mitigate before the next change window.
Description
Directory traversal vulnerability in setinfo.hts in HP Web Jetadmin 7.5.2546 allows remote authenticated attackers to read arbitrary files via a .. (dot dot) in the setinclude parameter.
- CVSS 2.0
- 2.1 LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 86.83% probability · 100th percentile
- CISA KEV
- Not listed
- Affected
- hp/web jetadmin
- Source
- cve@mitre.org
References
- http://marc.info/?l=bugtraq&m=108016019623003&w=2
- http://www.securityfocus.com/advisories/6492Vendor Advisory
- http://www.securityfocus.com/bid/9972Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15606
- http://marc.info/?l=bugtraq&m=108016019623003&w=2
- http://www.securityfocus.com/advisories/6492Vendor Advisory
- http://www.securityfocus.com/bid/9972Exploit, Vendor Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/15606
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.