CVE-2002-0196

GetRelativePath in ACD Incorporated CwpAPI 1.1 only verifies if the server root is somewhere within the path, which could allow remote attackers to read or write files outside of the web root, in other directories whose path includes the web root.
Advertisement

NeevaHost hosting service

Configurations

Configuration 1 (hide)

cpe:2.3:a:acd_incorporated:cwpapi:1.1:*:*:*:*:*:*:*

Information

Published : 2002-05-15 21:00

Updated : 2008-09-10 17:00


NVD link : CVE-2002-0196

Mitre link : CVE-2002-0196


JSON object : View

Advertisement

dedicated server usa

Products Affected

acd_incorporated

  • cwpapi