Quake3 Arena allows malicious server operators to read or modify files on a client via a dot dot (..) attack.
References
Link | Resource |
---|---|
http://www.quake3arena.com/news/index.html | Patch Vendor Advisory |
http://xforce.iss.net/alerts/advise50.php3 | |
http://www.securityfocus.com/bid/1169 | |
http://www.osvdb.org/7531 |
Configurations
Information
Published : 2000-05-02 21:00
Updated : 2008-09-10 12:04
NVD link : CVE-2000-0303
Mitre link : CVE-2000-0303
JSON object : View
CWE
Products Affected
id_software
- quake_3_arena