VulnerabilityModified
CVE-2005-4202
Multiple directory traversal vulnerabilities in LogiSphere 0.9.9j allow remote attackers to access arbitrary files via (1) ..
MEDIUM 5.0EPSS 3.42%
Does this matter?
Lower severity and a low EPSS score (3.42%). Track it; it rarely justifies an emergency change on its own.
Description
Multiple directory traversal vulnerabilities in LogiSphere 0.9.9j allow remote attackers to access arbitrary files via (1) .. (dot dot), (2) "..." (triple dot), and (3) "..//" sequences in the URL, (4) "../" sequences in the source parameter to viewsource.jsp, or (5) "..\" (dot dot backslash) sequences in the NS-query-pat parameter to the search URL. URL.
- CVSS 2.0
- 5.0 MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
- EPSS
- 3.42% probability · 88th percentile
- CISA KEV
- Not listed
- Affected
- logisphere/logisphere
- Source
- cve@mitre.org
References
- http://secunia.com/advisories/17989Vendor Advisory
- http://www.ipomonis.com/advisories/logisphere_server.zip
- http://www.securityfocus.com/bid/15807Exploit
- http://www.vupen.com/english/advisories/2005/2840
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23552
- http://secunia.com/advisories/17989Vendor Advisory
- http://www.ipomonis.com/advisories/logisphere_server.zip
- http://www.securityfocus.com/bid/15807Exploit
- http://www.vupen.com/english/advisories/2005/2840
- https://exchange.xforce.ibmcloud.com/vulnerabilities/23552
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.